>>any commercial application is likely to create extra unnecessary >>overhead and complications. a kernel based solution is much cleaner >>and lighter. yes, i have the ssh on top of it, but i can live with >>that. i'm using the tunnel for other things as well. > > Then openswan is probably your best bet. you know, i have 2 machines in my subnet, and my router is a 20 years old thing, with 64MB Ram, and 166 MHz... this openswan and vpn in general, seem to me dedicate for larger and more .... professional environments. I will look into your suggestion of using openswan, but (based on my knowledge so far) i would really prefer something more basic, light and simple searching more on the net I found some references to the RAWDNET and RAWSNET targets for the RAW table. but neither work with my iptables (ver. 1.4.0) is there any information available about this by any chance ? could you tell me anything more about the RAW table, that is not in the man pagel (there isn't much in the man page about this)? thanks! _________________________________________________________________ Connect to the next generation of MSN Messenger http://imagine-msn.com/messenger/launch80/default.aspx?locale=en-us&source=wlmailtagline-- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html