On Wed, 20 Feb 2002, Steve McAllister wrote: > The kernel is 2.4.7-10 and the masquerading is done via IPTABLES 1.2.4-2. I
> Module Size Used by > ip_conntrack_ftp 4080 0 (unused) > ip_nat_ftp 3680 0 (unused) I've seen problems like this but I can't remember which kernelversions. I know there was a problem with the rewriting of the ACK number in packets which have been modified, it sometimes calculated the wrong number and the transfer dies. This has been fixed in later kernels, please upgrade your kernel to 2.4.17 or something a lot more recent then that ancient 2.4.7 you are running. /Martin Never argue with an idiot. They drag you down to their level, then beat you with experience.