On Wed January 7 2009 16:36:20 Artūras Šlajus wrote: > I'm lost. And desperate. Where did we see your "iptables-save -c" output? I looked through the whole thread just now, can't find it. My WAG without seeing your rules is that they're complex and insane; also, I bet you're missing a state rule for return packets. SIMPLIFY. Start off with a nice simple ruleset that works, something along the lines of Rusty's Really Quick Guide to $FOO (for values of FOO of "Packet Filtering" and "NAT".) -- Offlist mail to this address is discarded unless "/dev/rob0" or "not-spam" is in Subject: header -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html