I googled and found that AH protocol pkt cannot be NATed , And ESP protocol pkt NATing wont work in some use cases . Is this problem is solved in newer kernels ? Is there any ALG for nating this packets ? Thanks, Ratheesh -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html