hi, I have been trying to set up shorewall for 2 ISPs and nothing fancy but am facing the problem that smtp,pop,ssh,ping and irc dont go through when I enable the masq. I am running Mandriva 2007. My setup is: eth0 192.168.2.201 - local lan eth2 202.x.x.3 gateway 202.x.x.1 isp1 eth3 222.x.x.3 gateway 222.x.x.1 isp2 my rules.drakx file: ACCEPT net fw udp 110,25,22 - ACCEPT net fw tcp 22,6670,110,25,22 - REDIRECT loc 3128 tcp www - my providers file: isp1 2 2 main eth2 202.x.x.1 balance,track eth0 isp2 1 1 main eth3 202.x.x.1 balance,track eth0 my masq file: eth2 202.x.x.3 222.x.x.3 eth3 222.x.x.3 202.x.x.3 If i comment out the entries in the masq file, everything works, but all traffic goes through eth2 only. If i enable the masq file, http works, load is balanced, but smtp,pop,ssh,ping and irc dont go through. Any clues? -- regards Kenneth Gonsalves Associate, NRC-FOSS lawgon@au-kbc.org http://nrcfosshelpline.in/web/ ------------------------------------------------------------------------- This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/