>> /sbin/iptables -A INPUT -i eth1 -d 0/0 -p tcp --dport 80 -j ACCEPT > > Everything looked good up to here. This rule needs to be in the FORWARD > chain. Once you've DNATted in PREROUTING, it's not coming to this > machine, it's being forwarded to another. I got it working now, thanks very much to you and Eric. Tom --