Hello,
You do not need to SNAT/MASQUERADE return traffic. The NAT code does it implicitly. However, the target host must have a (default) route back to the outside via the NATing gateway.The default gateway of the NATed machine was not the NATing gateway. The problem is now solved. Thank you very much.
Yours sincerely, Fülöp Balázs