Road:

I didn't "fix" it.... I couldn't without running around giving undeserved pos's to people...

As to your head hurting..... Imagine my head.... I know it was right.... I know that the change of default gateway _shouldn't_ matter because the routes on both the router and the firewall were correct, (the packets shouldn't have reached the firewall if they matched the route on the default gateway, which they did), but they still failed with a "destination host cannot be reached" for a whole A class when the route on the router was clearly a C class..... Do you have some _good_ Tynelol.... 'cos mine still doesn't seem to help.....

The router is internal, (behind the firewall)... It just serves the other networks I have... But it was set as the default gateway because the _expectation_ is/was that most traffic would remain internal to the network..... If it wasn't then it was sent to the firewall that had a default route that left my network for the "big wide world"....

I'm still not understanding _why_ the change of gateway makes it all work... but I'm going to sit with my sweetie and forget it until tomorrow......