Hi, I did the following $IPT -t nat -A PREROUTING -d <firewall> -p tcp --dport 1723 -i $EXT -j DNAT --to-destination <vpn>:1723 $IPT -t nat -A PREROUTING -d <firewall> -p gre -i $EXT -j DNAT --to-destination <vpn> $IPT -A FORWARD -i $EXT -o $RAS -d <vpn> -p TCP --dport 1723 -m state --state NEW -j ACCEPT $IPT -A FORWARD -i $EXT -o $RAS -d <vpn> -p GRE -m state --state NEW -j ACCEPT Do i need any modules? Thx for infos jo