argh. of course, i would spam a list shortly before finding the solution myself turns out i wasn't forwarding 0/0 from the DMZ network, only address from the DMZ range, so i wasn't actually receiving the replies to stuff sent out the ADSL connection. sorry for bothering you. Andrew Pilley