Alternatively, invokations of /usr/sbin/ipmasq can be added to two
(or four, depending on your underlying connection) scripts.
/usr/sbin/ipmasq must be added to your addroute and
delroute scripts. This will cause ipmasq to
re-evaluate the firewall when the proxy interface is established and removed.
brianb@debian.org