The strange thing, that the ping works well. If the far end has some routing problem, ping wouldn't work. I have the feeling, that the rc12 has some bug. I have 4 log rule at the beginning of the forward chain: 1. icmp to the other end, 2. icmp from the other end, 3. dst port 80 to the other end, 4....