NAT relies on port forwarding. To do pre/post routing, I believe you must indicate FORWARDING rules for incoming and outgoing traffic on that port:
$IPT -t filter -A FORWARD -i $INTIF -o $EXTIF -p tcp --dport 137 --syn -m state --state NEW -j ACCEPT $IPT -t filter -A FORWARD -o $INTIF -i $EXTIF -p tcp --dport 137 --syn -m state --state NEW -j ACCEPT $IPT -t filter -A FORWARD -i $INTIF -o $EXTIF -p tcp --dport 138 --syn -m state --state NEW -j ACCEPT $IPT -t filter -A FORWARD -o $INTIF -i $EXTIF -p tcp --dport 138 --syn -m state --state NEW -j ACCEPT $IPT -t filter -A FORWARD -i $INTIF -o $EXTIF -p tcp --dport 139 --syn -m state --state NEW -j ACCEPT $IPT -t filter -A FORWARD -o $INTIF -i $EXTIF -p tcp --dport 139 --syn -m state --state NEW -j ACCEPT $IPT -t filter -A FORWARD -i $INTIF -o $EXTIF -p tcp --dport 445 --syn -m state --state NEW -j ACCEPT $IPT -t filter -A FORWARD -o $INTIF -i $EXTIF -p tcp --dport 445 --syn -m state --state NEW -j ACCEPT Do you have similar forwarding rules? HTH, Mike -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba