*BEEP* *BUZZ* I know - but it's for a closed source app that I need to do this - and it takes the address from the server, the protocol doesn't carry it it :) -----Original Message----- From: Jan Engelhardt [mailto:jengelh@xxxxxxxxxxxxxxx] Sent: Mon 2007/05/07 18:01 To: Pieter De Wit Cc: netfilter@xxxxxxxxxxxxxxxxxxx Subject: Re: DNAT and local hosts On May 7 2007 17:54, Pieter De Wit wrote: > >Now, all connections are routed out via FW:ppp0 and at NAT'ed. There is >a rule that allows connections to ppp0 on port 1234 and DNAT's them to >C1. When C2 makes a connection to 1.2.3.4:1234 it fails with "Connection >refused" since there is no "server" listening on the firewall's >ppp0,port 1234. *BEEP* *BUZZ* *ERROR*. You have a direct connection between C1 and C2. Jan -- ?This e-mail is sent on the Terms and Conditions that can be accessed by Clicking on this link http://www.vodacom.co.za/legal/email.jsp "