Add --random option to DNAT and REDIRECT targets and fix the manpage mess this option left behind.
@@ -14,19 +14,17 @@ any established connections are lost anyway). It takes one option:
.BR "--to-ports " "\fIport\fP[-\fIport\fP]"
This specifies a range of source ports to use, overriding the default
-.BR "--random"
-Randomize source port mapping
source port-selection heuristics (see above). This is only valid
if the rule also specifies
.B "-p tcp"
.BR "-p udp" .
+.BR "--random"
+Randomize source port mapping
If option
.B "--random"
-is used then port mapping will be forcely randomized to avoid
-attacks based on port prediction (kernel >= 2.6.21).
+is used then port mapping will be randomized (kernel >= 2.6.21).