On Tue, Sep 16, 2003 at 01:57:39PM -0500, Jim Burnett wrote: > Correct. > > You cant DNAT to an IP which isnt bound to eth0 of that DNATed machine. > The gateway of the DNATed machine must point to the firewall also. This > isnt document. This was the case with 9 diferent tested linux distros. I'm sorry. You lost me here. What is "DNATed machine"? And what do you mean by "The gateway of the DNATed machine must point to the firewall"? Ramin