On Wed, Jun 04, 2003 at 11:12:37AM +0530, Dharmendra.T wrote: > Yes, but after that you are allowing everything from all the > interfaces. Which is not recommended to do so. > Eh? Which rules allow everything from all interfaces? I have the following, which only allow all packets with the right IP address range from internal interface and lo: $IPTABLES -A INPUT -p ALL -i $INTIF -s $INTLAN -j ACCEPT $IPTABLES -A INPUT -p ALL -i $LOIF -s $LOIP -j ACCEPT $IPTABLES -A INPUT -p ALL -i $LOIF -s $INTIP -j ACCEPT $IPTABLES -A INPUT -p ALL -i $LOIF -s $EXTIP -j ACCEPT Jun