Got it. Started using shorewall, and configured it per their instructions. Sorry to waste bandwidth :) -----Original Message----- From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of John York Sent: Thursday, January 16, 2003 20:27 To: netfilter@lists.netfilter.org Subject: Windows VPN server behind iptables Hi all, I set up my first IPtables box, doing NAT and port forwarding. I've managed to Google most of the kinks out, but this one perplexes me. There is a Win2K VPN server behind the firewall, using PPTP. It will accept connections, but chokes before accepting the username/password. The most I've been able to figure out is that it has something to do with protocol 47. All other forwards (HTTP, HTTPS, POP, SMTP, Telnet) work fine. Any ideas? Thanks, John