I've got the typical DNAT configuration working fine, but I'm wondering if there's a way to "port forward" without changing the source address of the packets so that the destination sees the actual client's IP? I've got a home-brewed load balancer running Pound for load balancing HTTPS traffic to a cluster of web mail servers but I'd like to have SMTP/POP/IMAP redirected to the single mail server without changing the source address so things like RBL's still work. This is to replace an existing LVS installation, if that provides some idea of the workalike I'm trying to build. I've Googled for hours in vain... Thanks, John -- John Madden Sr. UNIX Systems Engineer Ivy Tech Community College of Indiana jmadden@xxxxxxxxxxx - To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html