I digress. The documentation on iptables alone is an arduous read at best and requires dedication to get through and to understand. With that said, while you "cannot" (loosely said) follow any one singular packet from an iptables listing, using tcpdump will at least let you know wherefrom it connections originate and where they are terminating. Again, it is a hard read, not very beginner friendly, but I think it is also enough for the majority of threat models.
Question: does the person that feels that reading and understand iptables listings and tcpdumps really need to know - through an easy to read/understand UI - what chains and tables any one specific packet has traversed? What scenario/threat model/situation would that be? I'm all for discussing and widening my point of view, so don't hold back! 😊