Dear All, Can anyone explain why when connecting an internal win2k VPN client through an iptables firewall/gateway to an external VPN server, authentication should time out? I believe PPTP uses the GRE protocol (47) for authentication? So if I have flushed all the tables, set a default policy of ACCEPT for everything and set up masquerading then in theory it should work, right? Or must I explicitly ACCEPT these protocols/ports? George