On June 30, 2003 04:07 pm, Michael wrote: > > That's Squid looking up my domain. (Why twice? I don't know.) The OUTPUT > chain in the nat table is > > Chain OUTPUT (policy ACCEPT) > target prot opt in out source destination > DNAT tcp -- * * 0.0.0.0/0 1.2.3.5 multiport dports 80,443 > to:192.168.0.8 DNAT tcp -- * * 0.0.0.0/0 1.2.3.6 multiport > dports 80,443 to:192.168.0.9 > > Please read this page http://www.netfilter.org/documentation/HOWTO//NAT-HOWTO-3.html Why are you DNATting in OUTPUT? -- Alistair Tonner nerdnet.ca Senior Systems Analyst - RSS Any sufficiently advanced technology will have the appearance of magic. Lets get magical!