Hi, >I guess what's confusing me is that everything runs on the same box. Yup. Packet traverses nat table when it passes bridge and it cannot traverse this table second time entering virbr0 interface. Try this: echo 0 > /proc/sys/net/bridge/bridge-nf-call-iptables For permament solution add appropriate entry in /etc/sysctl.conf. Best regards, Marek -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html