On 01/02/2013 07:54 PM, Alan Evans wrote: > DNS queries (portal is also a DNS server) to the external > interface stop working. Hi, Please elaborate more. Why does 192.168.0.35 perform DNS queries against the "external interface" of the firewall? Why not use the internal ip? If you manually perform dig @192.168.0.1 google.com (I assume that's your firewall ip) from 192.168.0.35, does it work? Did you create the corresponding MASQUERADE rule (under POSTROUTING) for the egress traffic coming from 192.168.0.35? I believe so , otherwise you wouldn't have been able to connect from the outside to 20022. Please post your rules if you want more detailed help. I really don't see any relationship with what you describe & DNS problems. -- Jorge -- users mailing list users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines Have a question? Ask away: http://ask.fedoraproject.org