> > Yes, and I've added a rule like this: > > /sbin/iptables -t nat -A PREROUTING -j LOG and don't see the packets. > Ummmm > if you ADD the rule above after the rule that is re-routing the packet, > no ... you wont see the packets. Try > iptables -t nat -I PREROUTING (line number) > where (line number) is less than the line on which your DNAT line occurrs. > (see iptables -t nat --line-numbers -v ) I'm really replacing the DNAT rule with the LOG one (only rule in the chain is the LOG one) Saludos, HoraPe --- Horacio J. Peņa horape@xxxxxxxxxxxxxxxxx horape@xxxxxxxxxx