I have Mandrake 8 installed on a PII 450 box running a 2.4.4 kernel with all netfilter options compiled directly in the kernel. This machine does nothing but firewall and NAT duty. It has an external (serial port) 56k modem for the outgoing connect, and a realtek based 10/100 PCI card for the local net. I am using gShield (http://muse.linuxmafia.org/gshield.html) for the firewall. When i start a download from one of the client machines, it uses all the bandwidth. I can get some functionality from the firewall box itself, but none of the clients can ping anything not on the local net, including the one doing the downloading. This did not happen with ipchains on a 2.2 kernel. Is there an option I'm missing somewhere? Tim - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org