Hello. Currently, I want to implement an firewall as a semi-transparent gateway like this: when the firewall receive a SYN packet from client, it will pass to internal hosts. When the host response with SYN+ACK, the firewall forward it, but also generate and send an ACK packet that seem to come from client. I'm wonder are there any ways to implement this using netfilter framework + iptables or could anyone advising me a right way to do. Thanks you, HungNT. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html