> I always *NAT in PREROUTING and MASQUERADE in POSTROUTING if needed. According to the manpage for iptables, SNAT is only valid in the POSTROUTING chain. Is this incorrect? > Have never seen any such performance drop on multiple NIC. Neither have I, which is why this is bothering me. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html