RevJoe,
you have to use the internal addresses in the packet filters.
DNAT happens before routing and filtering!
SNAT and masquerading happen after filtering,
This means, if you work with any kind of NAT you
have to use the "internal" addresses in packet
filter rules!!!
Maybe this link is useful
http://packetstorm.widexs.nl/UNIX/firewall/ipchains/netfilter/netfilter-HOWTO.html
regards
ollion
[ 21 February 2002: Message edited by: ollion ]
This thread was automatically locked due to age.