On Thu, 2004-07-08 at 14:46, Daniel Pittman wrote: > If you can't, or don't want to, do that, then you need to make sure the > packet goes through the firewall in both directions, so you need to SNAT > any packet from an internal address to the public IP, so that the packet > is returned to the firewall. Would it be more sensible to SNAT it to the internal address of the firewall machine ?