My goal is to set-up an iptables rule that will match and DNAT the first HTTP(port 80) connection from a client (IP address). The first connection is defined as the first established TCP session from the time the iptables rule is inserted. No other TCP connection should match nor should be DNAT-ed. Is there any easy way to do this with current Netfilter/Iptables/pom. (I have installed almost all the patches from pom) -- Damjan Georgievski jabberID: damjan@xxxxxxxxxxxx