this is because ip gre tunnel (ip protocol 47) could not be established. You neet to apply pptp patch to iptables source and then use it. please read http://www.netfilter.org/documentation/HOWTO//netfilter-extensions-HOWTO.html Hello Dino, Friday, February 20, 2004, 1:17:37 PM, you wrote: DD> Hi, DD> I have linux Debian (2.4.24 kernel) firewall with nat and iptables.On my DD> private network there is MS w2000 pptp server. I can connect to it using pptp DD> from Internet (PPTP) but from only one client at the time.Is it DD> possible and how to connect through firewall several clients DD> simultaneously to vpn server? Iptables verison is 1.2.6a-5 DD> When I try to connect while there is already one connection I get DD> "Verifying username and password" until connection times out. DD> tx -- Best regards, Alexis mailto:alexis@xxxxxxxxxxxx