From FORWARDIN=eth0 OUT=eth0 SRC=vnc-client-ip DST=vnc-server-ip LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=31276 DF PROTO=TCP SPT=1612 DPT=5801 WINDOW=65535 RES=0x00 SYN URGP=0
eth0 is listed for both IN and OUT. That smells like a routing problem. The wrong interface chosen for OUT?