> > I am just curious: does it NAT, too? (This has nothing to do with your > > problem, whatever it may be.) Overlooked this question. No, the edge router does no natting -- just routes. We block private IPs going in/out the edge router -- that's how we handle them, and how we found these packets. By the way, here's some needed version numbers: iptables: 1.2.8 kernel: 2.4.20-28.8smp (yeah I know -- moving away from RH8 soon) Outside of these packets, NAT is working fine -- in fact, UDP and ICMP are being natted correctly outside of these packets. Thanks! -Dan