Sheldon Hearn wrote: > So basically, the SYN+ACK is arriving back at the firewall, but the > firewall then ignores it. If I add logging, I see the packet hit > PREROUTING, but that's it. Disable return path filtering on the interfaces. echo 0 > /proc/sys/net/ipv4/conf/eth0/rp_filter David