> Is host.ip the host from which you are trying to run lynx? > > This is strange behaviour, but it seems that problems occur when you are > trying to use conntack. Maybe conntrack modules are not loaded or some > rules in -t nat are acting like this. Does the nat table have rules? Can > you show it (iptables-save -t nat)? Show output of "lsmod | grep conn". Thank you for your suggestions. I've left DNAT rule in nat table - forgot about it. Then started retracing the steps again. The problem was with SNAT rule. With added additional entry in raw table for DNAT target everything started working. Thank you for your time. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html