* Antony Stone <Antony@xxxxxxxxxxxxxxxxxxxx>: > Which machine is that (192.168.1.2)? Is it the machine running the above > rules, or another machine on yur internal LAN, with packets being routed by > the netfilter box? The router has 192.168.1.250, 192.168.1.2 is the box the packets should be forwarded to. > Do you have a FORWARD rule allowing traffic to 192.168.1.2:80? > Do you have a rule allowing the reply packets (probably an ESTABLISHED,RELATED > rule)? The 3 rules from my first mail are the only rules I have. All chain policies are set to ACCEPT. > What happens if you telnet to port 80 on 192.168.1.2? Is there a service > listening on that port? Of course there is a running Apache on that port. I have no firewall on 192.168.1.2. The strange thing: the rule for portforwarding for SSH works. The package counter for that rules is increasing when I try to connect to that port. But there is now response. -- Kai Weber » kai.weber@xxxxxxxxxxx http://www.glorybox.de gpg-key: 0x594D4132