As opposed to using ipmasqadm portfw, I instead use redir, redir is a separate TCP wrapper. If you want to give it a whirl kick me off an email, I've already pre-compiled it so unless you want to compile it from src the binary should be sufficient.
Hope this helped,
Nathan