On Monday 19 September 2005 19:38, iptables-user wrote: > Thanks /dev/rob0!!! I laughed so hard I felt like *I* was full of > grog. (I'm part of a small circle of friends who talk like a pirate > on a regular basis. P) That's a good idea! I get rusty waiting for just one day a year. Brings to mind another holiday which should really be more than just one day: April Fools' Day. Alas, me hook an' pegleg an' eyepatch an' cutlass are all stowed away. > Everything now works without delay. Apparently specifying the output > interface in a FORWARD chain is not enough. By modifying the rule to > include -i AND -o things go where they're supposed to. Everything I wondered about this. I usually just do this by -i interface, and the return is covered by the RELATED,ESTABLISHED rule. But I thought your way should have worked too. -- mail to this address is discarded unless "/dev/rob0" or "not-spam" is in Subject: header