Hi, Where conntrack restores the address/port to original address/port of the reply packets before they leave outgoing interface? What is ip tables rule to hook on that place? It should be related to POSTROUTING but I have seen that the reply packets address/port on POSTROUTING NAT hook have not been restored. Best regards, -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html