I have forgotten iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE and now it works! Simple routing doesn't rewrite the source address. Alessandro Alessandro wrote: > > router:~# for f in /proc/sys/net/ipv4/conf/*/rp_filter; do cat $f ; done sorry: /proc/sys/net/ipv4/ip_forward was 1