Hello, I have an autonomous system: two providers, two routers, two class C IP address ranges but one interface on the firewall. On failure of one router/provider, both IP ranges would be served by the other one via a virtual IP. I may have two interfaces if needed... I need to protect a LAN, a DMZ, some point to point links and a few ssl tunnels. I've read the multiple internet connections document with little success, as my source NAT outgoing traffic sometimes gets set wrong source IP. Can you point me some clarifying docs? TIA, -- Marcelo "¿No será acaso que esta vida moderna está teniendo más de moderna que de vida?" (Mafalda) ------------------------------------------------------------------------------ Want fast and easy access to all the code in your enterprise? Index and search up to 200,000 lines of code with a free copy of Black Duck Code Sight - the same software that powers the world's largest code search on Ohloh, the Black Duck Open Hub! Try it now. http://p.sf.net/sfu/bds