Hi Geoff, pleased to help if I can.
I would add that iptables logging via LOG and ULOG will only log IP addresses
orts (and lots of other stuff, like TCP) flags of packets; it won't log an actual URL which is probably what you want.
What you might want to do is add Squid to your NAT box to provide proxying. This will have the added advantage of speeding up your local connection and providing logging of actual URLs. Squid can be complex to set up though.
Once I'm done getting ULOG and Squid working properly I'll post a HOW-TO; my project mandates that it be done by mid-June at the latest so it should be posted around then.