You have NAT enabled on the WAN interface and you want to port forward the communication from the spam filtering server? You have to add a new entry in the Virtual Server. This automatically adds a new entry on PREROUTING chain. If you are not using NAT then you will have to add a firewall rule in the FORWARD chain.
For your other question you can use ppp0 as you would use ETH00 or any other interface.