I presently exclude 1 ip block in POSTROUTING using "! X.X.X.X/24" . Is their a way to specify multiple ranges that are excluded? or Is their a way to have POSTROUTING only have affect on a certain interface? If anyone has a good link on this it would be appreciated, looked through some of the docs already but their are many more :-) Thanks, Ted