Hello Everyone, I was going through the RFC 2979[Behavior of and Requirements for Internet Firewalls]. There was a statement in the RFC saying firewall may "perform extensive protocol validity checks". How does iptables/Netfilter handle this one? Does the unclean match support this? If so what are the protocols that unclean match support? I checked the man page, there is no much explanation regarding the same. Narendra. ------------------------- Narendra Prabhu. B DeepRoot Linux http://www.deeproot.co.in