I use Debian 5.0 with kernel 2.6.31 compiled with tproxy dmesg |grep TPROXY I downloaded ad installed iptables from git.balabit.hu/bazsi I use current squid (version squid-3.HEAD-20090929) with options '--enable-linux-netfilter' I can't open web page from client. The following error was encountered while trying to retrieve the URL: http://www.whatismyip.com/ Connection to 72.233.89.199 failed. The system returned: (110) Connection timed out The remote host or network may be down. Please try the request again. in squid log i see 2009/10/02 01:39:32.709| PconnPool::key(www.whatismyip.com,80,(no domain),xxx.xxx.xxx.xxxis {www.whatismyip.com:80-xxx.xxx.xxx.xxx} 2009/10/02 01:39:32.709| PconnPool::pop: lookup for key {www.whatismyip.com:80-xxx.xxx.xxx.xxx} failed. 2009/10/02 01:39:32.709| FilledChecklist.cc(162) ~ACLFilledChecklist: ACLFilledChecklist destroyed 0xbfaf5d38 2009/10/02 01:39:32.709| ACLChecklist::~ACLChecklist: destroyed 0xbfaf5d38 what problem ? it's problem in kernel, iptables or squid ? please help !!! Thanks Roman -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean.