Magnus et al, I have several Linux firewall/gateway machines dotted around the UK and Europe which are basically RedHat 7.3 + Kernet 2.4.20 + iptables 1.2.7a. We have things on the inside like Cisco VoIP phones, print servers, etc. that need to be able to TFTP code or configs in from a server on the outside (public internet). TFTP appears not to work and when I search google I find information which refers to patches to "oldnat" but not to "newnat". Is there something that I am missing? Is there a configuiration module, helper, patch or something for iptables 1.2.7a which will fix this? Mike