Another question that's been bugging me: When does the actual NAT process (i.e., swapping addresses) take place for DNAT and SNAT/MASQUERADE? And when does the reciprocal NAT (i.e., reverse NAT, that should happen for instance to process a reply to a packet that's been SNAT-ed) take place? My guess is just after the packet exits the nat table, before it enters the mangle table. Am I correct? Rgds, -- -- Pandu E Poluan - IT Optimizer My website: http://pandu.poluan.info/ -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html