It's odd but for some reasons it only fails with Microsoft PPTP implementation. It seems to be too picky about something. Unfortunately my c skills are rusty and I'm usually strapped for time otherwise I would delve into it and try to help them out. I'm inclined to include James Cameron in this (from the pptp and poptop sites) as he seems to have a much better understanding of the protocol than I do. Maybe he can help out so we can try to implement the functionality in the 2.6 kernel. Gary > -----Original Message----- > From: netfilter-bounces@xxxxxxxxxxxxxxxxxxx [mailto:netfilter- > bounces@xxxxxxxxxxxxxxxxxxx] On Behalf Of Marty Phee > Sent: Thursday, March 03, 2005 3:22 PM > To: netfilter@xxxxxxxxxxxxxxxxxxx > Subject: Re: VPN through the firewall > > > Gary W. Smith can speak to this much better than myself, but 2.6 + > > pptp/gre conntrack/nat is not a winning combo, AFAIK... > > That sucks. Why exactly? What causes problems. >