In article <5.0.0.25.0.20001220115927.00b97c60@mail.vocalscape.com> you wrote: > My understanding is that the firewall will reply to arp requests for each > (30) external IP address we have with its own MAC address, thus tricking > computers on the internet in to sending packets destined for any of our > external IPs to our firewall. From there the firewall can route the packets > to each client behind it with little difficulty? Yes, but the firewall has to answer with the MAC Address of the interface attached to the clients network. And it will do that if you use the auto-arp featue automatically. >> > echo 1 > /proc/sys/net/ipv4/conf/all/proxy_arp Greetings Bernd - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org