hi I need to exclude some ip addres and a lan in a rule of iptables that redirect the www to my squid proxy. The rule is iptables -t nat -A PREROUTING -i eth0 -d ! 192.168.200.220 -ptcp --dport 80 -jREDIRECT --to-ports 3128 PS: i use this rule to redirect squid proxy in this machine that not is my firewall linux (is a faq of shorewall redirect with iproute). How could i exclude some ip address to this line? i always use shorewall so i don''t know to write with hand the line.. thankx to helping me. Bye. Luca -- =======================================Andreoli Luca System Support Division Kelyan SMC S.p.a. - Franco Bernabè Group E-Mail: l.andreoli@kelyansmc.it ========================================