Using the native IPSEC code in kernel 2.6, when a tunneled ESP packet is passed by the INPUT chain and then decoded on a VPN gateway, is it then processed by any other chain? -- Jeff Simmons jsimmons@xxxxxxxxxxxxxxx Simmons Consulting - Network Engineering, Administration, Security "You guys, I don't hear any noise. Are you sure you're doing it right?" -- My Life With The Thrill Kill Kult