Thanks for the quick reply. Unfortunately, NETMAP seems to be a static version of standard NAT. What I need is to replace the source address during prerouting and the destination address during postrouting. Thereby hiding the true IP of an interface from the system. Any ideas? Kind regards, tannador -- Sent from my smartphone. Pardon typos and the short form. >Did you look at the NETMAP iptables target? > >Mit freundlichen Grüßen/Regards, >Noel Kuntze -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html