The dropbear ssh client on Tomato 1.28 doesn't appear to support the -D option for dynamic forwarding, so I'm trying to use an iptables rule to DNAT specific source IPs to go through another box on the network which has a tunnel already established. The command used to establish the tunnel was run like so: ssh -fgND 23432 user@host The iptables rule I am running from the router is: # iptables -t nat -A PREROUTING -p tcp -s 10.1.2.3 -j DNAT --to 10.1.2.2:23432 In this scenario, 10.1.2.3 is the computer whose connections I want to send through the tunnel, and 10.1.2.2 is the box running the SSH tunnel. The problem with this, however, is that the connection doesn't actually get forwarded over the ssh tunnel. I'm not an iptables expert, but I believe this has to do with the fact that the source IP wasn't modified, so it looks like I am creating a loop here. Is there a good way around this problem?