Hi, >Ideal cases once the reply comes back GW has to send it to the host H1 >right ? >Sorry if I am wrong or missed any steps down here ? Please send output of following command: sudo iptables-save -t filter I bet you're filtering traffic destined to H1 from eth1 in FORWARD chain of filter table. Best regards, Marek Kierdelewicz -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html