Hi, As no solution appeared, I try again, here is my config (figure clarified by Darryl Miles) 10.67.28.0/24 -----------+----------------------------------+----------- eth1 | 10.67.28.2 eth1 | 10.67.28.1 +-----+-----+ +-----+------+ | FIREWALL | | HOST | | | | | +-----+-----+ +-----+------+ eth0 | 10.67.27.2 eth0 | 10.67.27.1 -----------+----------------------------------+----------- 10.67.27.0/24 The question: >From the host, how to force a packet destined to 10.67.27.1 to go through the firewall since route add -host 10.67.27.1 gw 10.67.27.2 dev eth0 is not enough ? Thanks for your help - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org