Hi! On Mon, Nov 28, 2005 at 02:02:56PM +0530, Aseem Rastogi wrote: > also traffic from local machine doesn't pass through PREROUTING chain > . add this rule to OUTPUT chain of NAT table. i already tried that. But: # iptables -t nat -A OUTPUT -p tcp -d ! 192.168.100.0/24 --dport 25 -j DNAT \ --to 127.0.0.1:25 iptables: Invalid argument Regards, Martin