Is it safe to assume packets diverted to NAT are "safe" and don't need further checking? In particular, can the use of dynamic/stateful rules be skipped for NAT packets? It seems so, because NAT is already stateful.