This adds a `drop' table to iptables.  Packets which are going to be dropped
by the NAT or routing code (among others) will traverse this table, allowing
them to be logged.
