I have a probably common SIP NAT/NAPT problem and I want to see how others have solved this issue: I want to dynamically create DNAT rules for RTP streams (port-mapping for a SIP proxy). This works fine when I add a rule before the first packet of the RTP stream hits the port. But, if the RTP stream begins before the rule is in place, it never matches. I can insert the DNAT rule only after I have the SDP part of the 200 OK (or any other 1xx with a SDP body). Rgds Jimmy -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html