Hello I'm wondering if state doesn't apply to ICMP packets. iptables -A FORWARD -p icmp -m state -d --state NEW -j ACCEPT iptables -A FORWARD -m state --state NEW,INVALID -j REJECT if I ping the echo-reply is blocked from Is this normal, I thought that the echo-reply should be marked RELATED and therefore not blocked? ==== Tomas Edwardsson HP Technical Support \ HP Certified System Administrator Red Hat Technical Support \ Red Hat Certified Engineer. Opin Kerfi