> /sbin/iptables -A FORWARD -p tcp -i eth1 --dport 21 -j ACCEPT > /sbin/iptables -A PREROUTING -t nat -p tcp -i eth1 --dport 21 > -j DNAT --to > 10.0.0.199:21 Do you also have something like : /sbin/iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT Rob