The other gotcha is that masquerading doesn't seem to be there yet for 2.4.* Not a biggie for me, YMMV
Yes it is! Check out netfilter/iptables. I have a firewall on a 2.4.3 kernel, running iptables and masquerading for a LAN as I type!
OK, how do I get equivalent functionality to ip_masq_* ? Especially quake...