-> > -> > lsmod: -> > -> > -> > -> > Module Size Used by Not tainted -> > -> -> > -> ... -> > -> -> > -> > ip_nat_proto_gre 1508 0 (unused) -> > -> > ip_nat_pptp 2572 0 (unused) -> > -> -> > -> I'm not sure ; perhaps you need to unload ip_nat_pptp. I thought -> > you -> > -> needed this when *you* run a PPTP server *behind* the firewall. -> > -> > Thank you, but PPTP server is located on Internet, not behind -> > firewall. -> -> Yes, that's why I mentioned it : you have the same situation as I had -> back then and I needed to unload this module. But, YMMV. outch !! -> Still, we don't know what you rule have so far concerning pptp... -> It's a little hard to give advice this way. I only have a "MASQUERADE" rule in POSTROTING nat table. That's all. I need a specific rule to masquerade VPN ? thank you