On May 7 2007 17:54, Pieter De Wit wrote: > >Now, all connections are routed out via FW:ppp0 and at NAT'ed. There is >a rule that allows connections to ppp0 on port 1234 and DNAT's them to >C1. When C2 makes a connection to 1.2.3.4:1234 it fails with "Connection >refused" since there is no "server" listening on the firewall's >ppp0,port 1234. *BEEP* *BUZZ* *ERROR*. You have a direct connection between C1 and C2. Jan --