hello all , 1. actually i m doing SANT to convert my 10.10.189.125 ip to 192.168.14.190 to make the ftp connection in the same LAN. So , doing the same , i m SANTind 10.10.189.125 to 192.168.15.190. but i want to know that , if i m doing the SNAT one of the inteface , then will i have to do DNAT at the same interface to convert the destination address (in the packet coming form lan to my machine i.e. 192.168.15.190) into my machine's address i.e 10.10.189.125.?? or kernel will take care of that ? 2. agian , i want to make only ftp from my machine to any to LAN machine , so for that i wrote some rule set , everything is going well , but when i ftp to lan machine , it makes the connection successfully , but when i run "dir" or "ls " command , it shows nothing and behaves like hang. so , plz help me .............