Hello Guys, I have the following setup: C1 --. | |-FW--- internet | C2 --' Ok - for this email, I will give C1 192.168.0.10 and C2 192.168.0.11. The Firewall (FW) has two ethernet connections, eth0 and eth1. eth1 is used to an adsl modem in bridged mode, which creates ppp0. Lets say for this email, ppp0 get 1.2.3.4. Now, all connections are routed out via FW:ppp0 and at NAT'ed. There is a rule that allows connections to ppp0 on port 1234 and DNAT's them to C1. When C2 makes a connection to 1.2.3.4:1234 it fails with "Connection refused" since there is no "server" listening on the firewall's ppp0,port 1234. How can I solve this ? I need FW to DNAT "local/C2" connections back to C1. Thanks, Pieter ?This e-mail is sent on the Terms and Conditions that can be accessed by Clicking on this link http://www.vodacom.co.za/legal/email.jsp "