Yes, the iptables service is running:
[root@gateway ~]# chkconfig --list iptables
The FORWARD and OUTPUT chains are showing packets and bytes being processed. In order to get the FORWARD chain working I had to modify the /etc/sysctl.conf file to include this:
net.ipv4.ip_forward = 1
Maybe there's a similar option for the INPUT chain? I read the sysctl man pages but it didn't say, so I'm googling it now...