Am Sam, 2003-11-29 um 01.56 schrieb zynkx: > i'm sure i have ip forward enabled, since gateway 2 is > working fine and routing packets ok through the lan > and to gateway 1. if it happened not to have ip > forward enabled in gateway 2 i could never do > masquerading from gateway 2 to gateway 1 :) > dhcrelay is a local application. It works as a proxy. You have to allow incoming packets on broadcast and unicast address in your INPUT chain. Again the OUTPUT chain must be open, too. DHCP is not forwarded. > i'm gonna test it with no firewalling at all to see > what happens ;)) It won't work. Cheers, Ralf -- Ralf Spenneberg RHCE, RHCX Book: VPN mit Linux Book: Intrusion Detection für Linux Server http://www.spenneberg.com IPsec-Howto http://www.ipsec-howto.org Honeynet Project Mirror: http://honeynet.spenneberg.org