> Hmmm . . . I'll have to defer to others who know more about modules. I > always compile mine as part of the kernel just in case. I see the > iptable_nat so I'm not sure what's missing. Is there any chance the > userland tools are mismatched to the kernel? > -- unfortunately not. otherwise i could change something. both machines are clean and selfmade from scratch. the differential of the second mashine is the kernelversion 2.4.22 with CONFIG_KMOD --> y. but on the real firewall i wont do anything automaticly. on a third mashine kernel 2.4.26, iptables 1.2.9 and all of modules are build in kernel, a rule with DNAT in a userchain also wont work. i believe nearly in an error on the second mashine :( Jan