Excellent! : martin, you are truly the greatest network hacker around. <SMILE/> : i works like a charm, i removed the two rules that said "from : <if-address>, use table 'main'", and used the one you provided. I realized upon re-reading my post of last night, that I didn't explain what "ip rule add iif lo" means. It is an idiom describing locally generated packets. I'm very happy that is working for you. -Martin -- Martin A. Brown --- SecurePipe, Inc. --- mabrown@xxxxxxxxxxxxxx