Hi. Main firewall PREROUTING Chain: ACCEPT all -- 192.168.10.x0 0.0.0.0/0 ACCEPT all -- 192.168.10.x1 0.0.0.0/0 ... DNAT tcp -- 0.0.0.0/0 x.y.z.v multiport dports 80,22,8180 to:192.168.30.y REDIRECT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 redir ports 80 192.168.10.x0, 192.168.10.x1 internet enabled, other internal ip 192.168.10._ redirect main server 80 port. server x.y.z.v DNAT DMZ, if 192.168.10.x0, 192.168.10.x1 send http: to x.y.z.v pub.ip-address, then send my REDIRECTED SERVER. WHILE? by gab ---------------------------------------------------------------- This message was sent using IMP, the Internet Messaging Program.