I think he miss some -o $iface in his rule. Otherwise to much stuff get SNAT-ed :) And yea, i was thinking on NETMAP. If adding the correct -o wont work, then the output of route -n and your nat rules might help. On Tue, 21 Sep 2004 13:27:45 -0400, Jason Opperisano <opie@xxxxxxxxxxx> wrote: > On Tue, 2004-09-21 at 12:43, George Alexandru Dragoi wrote: > > http://www.netfilter.org/patch-o-matic/pom-base.html#pom-base-SAME > > > > > > did you mean: > > http://www.netfilter.org/patch-o-matic/pom-base.html#pom-base-NETMAP > > and the OP's problem was one of ARP--not NAT. > > -j > > -- > Jason Opperisano <opie@xxxxxxxxxxx> > > -- Bla bla