Sorry those are my rules (DMZ) HTTP # iptables -t nat -A PREROUTING -p tcp -d $IP_REAL --dport 80 -j DNAT \ --to-destination $IP_DMZ iptables -t nat -A POSTROUTING -p tcp -d $IP_DMZ --dport 80 -j SNAT \ --to-source $IP_LAN iptables -t nat -A OUTPUT -p tcp -d $IP_REAL --dport 80 -j DNAT \ --to-destination $IP_DMZ # # # work great with rh 7.1 kernel 2.4.17 ----- Original Message ----- From: "Leszek Zur" <lzur@xxxxxxxxxxxxx> To: <netfilter@xxxxxxxxxxxxxxxxxxx> Sent: Thursday, May 22, 2003 10:01 AM Subject: POSTROUTING & DNAT > Hello > > iptables -t nat -A OUTPUT -d 1.1.1.1 -j DNAT --to-destination 2.2.2.2 > iptables: Invalid argument > > Can anyone help me understand what is happening? > > iptables v1.2.8 > kernel 2.4.20 > > thnx > > Leszek > > >