Hi, just configured a shorewall-box with identical setting as a machine which works for passing pptp via dnat to an internal pptp server (win). Unfortunately we cannot establish a connection and tcpdump tells (from firewall to client) icmp: my_host protocol 47 unreachable [tos 0xc0]. What could I do now, to troubleshoot? We followed exactly the dnat settings in your docu. Thx Andy