>> Maybe you could give server's address to firewall ;-) Then you don't >> have to touch router's configuration.
Good idea! But is it a Good Thing? mhhh... yes, it seems! Ok, as a definitive solution I'll do it and update to iptables to re-NAT the real address of the server. For now I'll just enable bridging in the kernel and filter connections in the 'bridge' chain of ipchains. It's faster enougth! By the way, I have to patch the kernel 2.2.17 (or 18 or 19) to do bridging, isnt'it? Thanks to all replies, Marco Tassinari [EMAIL PROTECTED]