But then again, would it hurt the kernel to borrow the port from the tcp port pool when it becomes actively masqueraded? I know that i can separate my ephemeral ports from my --to-ports. However, ephemeral port selection algorithms should use the whole range 1024-65535. -- it sounds like the value of ip_local_port_range should not be used anyway.