The problem is that IPFilter assumes that the checksum will be fixed after control is returned to the IP code.
The obvious solution is to have the bridge recalculate the IP header checksum after every packet comes back from ipfilter to send out. Darren
