grep wrote on Mon, 16 December 2013 09:52So your server answers.
Can you ssh into it? is only http refused?
iptables from ve (iptables-save in terminal to show all)? 
I get "Connection refused" from VE to host for all ports, that was redirected in the host with
iptables -t nat -A PREROUTING -p TCP -i eth0 --dport 80 -j DNAT --to 10.0.0.3:80
I have no such forwarding rule on port 22, so I have no problem. Here is summary of different scenarios
                     |  Non-redirected port (22)  |  Redirected port (80)  |
----------------------------------------------------------------------------
Outside -> Host      |  OK                        |  OK                    |
5.6.7.8 -> 1.1.1.1   |                            |                        |
----------------------------------------------------------------------------
VE -> Host           |  OK                        |  Connection refused    |
10.0.0.3 -> 1.1.1.1  |                            |                        |
----------------------------------------------------------------------------
There are no iptable rules in the VE.
I am far from expert in this and may be wrong, but I suspect that I have "NAT loopback" issue like described here http  ://en.wikipedia.org/wiki/Network_address_translation#NAT_loo pback