In comments in file ip_fw2.c i read: * Dynamic rules can be used for different purposes: * + stateful rules; * + enforcing limits on the number of sessions; * + in-kernel NAT (not implemented yet) When will implemented in-kernel NAT? Regards, Denis