Well, you didn't put in default deny policies and logging of packets that hit the end like I suggested. If you did, I'm guessing you might see the pkts coming from the windows http server being denied. Something is keeping those Acks from getting back to the client. And it is either 1. the windows box is not sending packets back to the router (you can check with tcpdump) or 2. the router is not forwarding the Acks back to the client. I don't think you've read the docs. -- Dale Bewley - dlbewley@ucdavis.edu Unix Server Administrator / Digital Library Consultant -- Psyche-list mailing list Psyche-list@redhat.com https://listman.redhat.com/mailman/listinfo/psyche-list