Hy my name is Giorgio, I'm tryng to translate our Checkpoint FW-1 ruleset into Iptables. I do not know iptables well so I really need a suggestion to plan my future efforts. The problem is this: Is it possible to use objects like Checkpoint Groups (that is a set of host and/or networks) into an Iptables rule. It seems to me that iptables accept souce/destination that are only one host/network. Thanks Giorgio