>I think you simply need to remove the "-d 161.x.x.x/21" from your rule and >things will start working the way you want. > >Regards, > just wanted to make sure this is right. iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o eth0 -j SNAT --to 161.x.x.x <iptables -t nat -L -n> gives me Chain PREROUTING (policy ACCEPT) target prot opt source destination Chain POSTROUTING (policy ACCEPT) target prot opt source destination SNAT all -- 192.168.0.0/24 0.0.0.0/0 to:161.x.x.x is that right? so that should mask my internetwork? john http://www.arbbs.net/