On Wed, 2003-03-05 at 17:36, Sven Schuster wrote: > What you need is the mport-match: > > iptables -A FORWARD -p tcp -m mport --sport 5000:5020 -m state ... mport is not needed for a simple range -- /Martin Never argue with an idiot. They drag you down to their level, then beat you with experience.