The MANGLE table is used to alter certain properties of packets as they traverse the firewall. You can change the TOS (type of service), TTL (time to live), and MARK .

The TOS is used by (some) routers to make routing decisions, as is the MARK. They are useful for internal routing on a large network, and various esoteric rituals. However, these properties are poorly implemented on the internet at large, so these fieldsare little use for traffic bound for the intraweb.

The only example I have seen for MANGLEing the TTL of packets is to disguise multiple computers sharing an internet connection, althoght there are doubtless many subtle and confusing applications.

(This really ought to be part of JCCyC's w/u above, 'cos he explains iptables better than I could. Just filling a gap :-)