On Thursday, September 19, 2013 12:36:30 PM iptables@xxxxxxxxxxx wrote: > Hello: > > I'm trying to set up simple NAT/masquerading on a dual NIC host > (hostname == "psi") running fedora 19, so hosts on my LAN can access > Internet by routing thru host "psi". > > Interface p1p1 is on my LAN, p2p1 is on Internet. > > I got the "design" of below /etc/iptables from another of my older (fedora > core 10) hosts, where NAT/masquerading works fine. > > Everything but the NAT/masquerading works. Perhaps I missed it: where do you ACCEPT *NEW* conns in chain FORWARD? -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html