> iptables -A FORWARD --match mac --mac-source 00:c0:49:c9:d3:f1 -j MASQ You need:iptables -A FORWARD --match mac --mac-source 00:c0:49:c9:d3:f1 -j MASQUERADE Cheers, Ralf -- Ralf Spenneberg RHCE, RHCX Book: Intrusion Detection für Linux Server http://www.spenneberg.com IPsec-Howto http://www.ipsec-howto.org Honeynet Project Mirror: http://honeynet.spenneberg.org