>However, when a local users tries to connect to the public IP and DNATed >port, the connection fails. Which is basically logical as the server >receives a packet with the source IP of the actual user and it answeres >directly to that IP. Is it possible to change netfilter behaviour? Any >other work-around for that? As Samuel noted, that is described here: http://www.netfilter.org/documentation/HOWTO/NAT-HOWTO-10.html and I elaborate on it here: http://idallen.com/dnat.txt -- -IAN! Ian! D. Allen Ottawa, Ontario, Canada EMail: idallen@xxxxxxxxxx WWW: http://www.idallen.com/ College professor (Linux) via: http://teaching.idallen.com/ Support free and open public digital rights: http://eff.org/