Le ven 13/06/2003 à 09:24, Kent Wang a Ãcrit : > A properly DNATâd packet should pass through FORWARD and then OUTPUT, > but I found nothing in the log. A forwarded packets only crosses FORWARD chain. Framework has changed from ipchains' one. Now, a given packet goes through one filter table chain, and one only, depending it is destined to the hosts, destined to be routed or locally generated. If your DNAT implies packet to get routed, then you'll them in FORWARD chain. Otherwise, you'll see them in INPUT chain. > Any clues? Well, read the doc. -- CÃdric Blancher <blancher@xxxxxxxxxxxxxxxxxx> IT systems and networks security - Cartel SÃcurità Phone : +33 (0)1 44 06 97 87 - Fax: +33 (0)1 44 06 97 99 PGP KeyID:157E98EE FingerPrint:FA62226DA9E72FA8AECAA240008B480E157E98EE