My goal is to set-up an iptables rule that will match and DNAT the first connection from a client. The first connection is defined as the first established TCP session from the time the iptables rule is inserted. No other TCP connection should match nor should be DNAT-ed. Is there any easy way to do this with current Netfilter/Iptables/pom. (I have installed almost all the patches from pom) -- Damjan Georgievski jabberID: damjan@xxxxxxxxxxxx