Marty, If you are NAT'ing you will need to check out the pptp conntrack modules which would probably require a kernel recompile. Gary Smith ________________________________ From: netfilter-bounces@xxxxxxxxxxxxxxxxxxx on behalf of Marty Phee Sent: Wed 3/2/2005 2:33 PM To: netfilter@xxxxxxxxxxxxxxxxxxx Subject: VPN through the firewall I've got a SUSE box running my home firewall and a WinXP work machine that I use to VPN into the office network. Before I put this SUSE 9.2 in I had a Mandrake 9.1 box that worked just fine. Everything but my VPN connection to the office works. I've added all kinds of rules to try to get this to work, but nothings working. I don't see any packets getting dropped/rejected. It looks like it makes the connection to the vpn server, but it's not verifying the password. With Ethereal I see this: Source: 129.230.241.140 Destination: 192.168.0.73 Protocol: EAP Info: Request, EAP-TLS [RFC2716] [Aboba] That line just keeps repeating until it timesout with a 619 on the windows machine. Help would be greatly appreciated!