Hmmm, I use the external interface in ipnat.conf and not the internal one for the mapping a rfc1918 address.
Yeah - I got a bit over-zealous when updating things for the new nic. It was the _internal_ net's nic that I replaced; I have no idea why I thought I should change ipnat.conf
I assume IP forwarding is enabled.
Yep. ------------------------------------------------------------------------- | Paul Goyette | PGP DSS Key fingerprint: | E-mail addresses: | | Customer Service | FA29 0E3B 35AF E8AE 6651 | paul at whooppee.com | | Network Engineer | 0786 F758 55DE 53BA 7731 | pgoyette at juniper.net | | Kernel Developer | | pgoyette at netbsd.org | -------------------------------------------------------------------------