Hello. I have some clients in my LAN that need to access ICQ and MSN Messenger. Reading some iptables tutorials, I discovered that ICQ and MSN Messenger protocols are some kind of "complex protocols" because they send some information about openning new connections back inside the payload of the packets. So, iptables needs some CONNTRACK and/or NAT helpers to let this protocols work properly. I looked for it on NETFILTER home page but I didn't find it. So, I need some help about it! Where can I get an how to apply it on my iptables? (Do I have to use patch-o-matic?) Besides, I want to use the FORWARD chain instead of sending this protocols via SQUID or another proxy. Some solution? Regards Giancarlo _______________________________________________________ Yahoo! Messenger 6.0 - jogos, emoticons sonoros e muita diversão. Instale agora! http://br.download.yahoo.com/messenger/