Do you have FORWARDing rules on both gateways allowing TCP port 25 packets from your internal network to the mail server?
Ah, ha! That was the problem. The proper FORWARDing rule was absent (which is why I had posted to the netfilter mailing list instead of some mailing list about routing). I added the rule and things are going great.
Thanks a bunch.
Thaths -- "Trying is the first step towards failure." -- Homer J. Simpson Slacker Without Borders http://openscroll.org/ Key fingerprint = 8A 84 2E 67 10 9A 64 03 24 38 B6 AB 1B 6E 8C E4