My best guess would be to move your forwarding rules to the INPUT chain instead of being in the PREROUTING. On Tue, Dec 13, 2011 at 10:16 AM, Laurent Wandrebeck <l.wandrebeck@xxxxxxxxx > wrote: > On Tue, 13 Dec 2011 10:07:41 -0500 > cliff here <c4ifford@xxxxxxxxx> wrote: > > > sorry that's watch -n 1 'iptables -t nat -L -n -v' > <snip> > > > But if not mistake about what your intent is your forwarding rules that > > > you have in prerouting should be in INPUT chain. > > > You're trying to come in from an outside net to your FW and be > forwarded > > > to what you have NAT'd behind it right? > absolutely. > I've updated fpaste with /etc/sysconfig/iptables > Thanks. > _______________________________________________ > CentOS mailing list > CentOS@xxxxxxxxxx > http://lists.centos.org/mailman/listinfo/centos > -- ------------------------------------------------------------------------------------------------------------------------------------- NOTICE: This message, including all attachments, is intended for the use of the individual or entity to which it is addressed and may contain information that is privileged, confidential and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient, or the employee or agent responsible for delivering this message to its intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the sender immediately by replying "Received in error" and immediately delete this message and all its attachments. ------------------------------------------------------------------------------------------------------------------------------------- _______________________________________________ CentOS mailing list CentOS@xxxxxxxxxx http://lists.centos.org/mailman/listinfo/centos