I have a SNAT rule for our IPFire email server which NATs all outgoing SMTP connection to the public IP address of the mail server. That rule also NATs all SMTP packets that are going through a VPN which I did not expect. The source of the rule is the IP address of the email server, destination is RED. There should be entries in the SNAT table for all non-NAT rules that just run ACCEPT so that NAT never happens for those rules where it is not intended.
*** This bug has been marked as a duplicate of bug 12162 ***