Louis Lagendijk wrote: > How are you connecting to the internet: through ppp0? Why are you using > DNAT? If you have the fixed IP address on ppp0, all you need to do is > setting the appropriate ALLOW rule: > AllowWeb net fw > as you don't need to forward traffic to another machine. Thank you very much; I followed your advice, removed the two DNAT lines I had added to my shorewall rules, and added the line you suggested: AllowWeb net fw This worked like a charm, and appears to have solved my problem completely. -- Timothy Murphy e-mail (<80k only): tim /at/ birdsnest.maths.tcd.ie tel: +353-86-2336090, +353-1-2842366 s-mail: School of Mathematics, Trinity College, Dublin 2, Ireland