Hi, I am on a linux box (mdk 9.1) which is connected to net. I want to allow internal windows machine 192.68.10.x to browse the net and anything (NAT). But nobody should be allowed to access any port from outside the LAN. Except for ftp services on port 21. I have a problem understanding the default DROP policy and then opening required ports. Can someone give an example on this please? Thanks a lot in advance and bye. With warm regards, -Payal -- For GNU/Linux Success Stories and Articles visit: http://payal.staticky.com