On Tuesday 18 May 2004 4:40 pm, alucard@xxxxxxxxx wrote: > > Kernel IP routing table > > Destination Gateway Genmask Flags Metric Ref Use > > Iface > > 192.168.0.0 * 255.255.255.0 U 0 0 0 > > eth1 > > 10.73.216.0 * 255.255.252.0 U 0 0 0 > > eth0 > > 169.254.0.0 * 255.255.0.0 U 0 0 0 > > eth0 > > 127.0.0.0 * 255.0.0.0 U 0 0 0 > > lo default 192.168.0.1 0.0.0.0 UG 0 0 > > 0 eth1 > > > > If the requests come in on eth1 but the replies go out on eth0 that would > > be a > > problem. > > well, in server2 -the one that that has to get the packets forwarded from > server1- 192.168 network is in eth1, does anybody see anything wrong with > it's route configuration? any suggestions?? Yes, but where are you doing the nmap testing from? Surely not the machine with the nat rules on it?? (That won't work.) Server 2 has to have a route to send the reply packets back to the machine doing the testing. The packets will not have the source address of server1. Regards, Antony. -- In Heaven, the police are British, the chefs are Italian, the beer is Belgian, the mechanics are German, the lovers are French, the entertainment is American, and everything is organised by the Swiss. In Hell, the police are German, the chefs are British, the beer is American, the mechanics are French, the lovers are Swiss, the entertainment is Belgian, and everything is organised by the Italians. Please reply to the list; please don't CC me.