Am Mit, 2003-09-03 um 10.43 schrieb Sven Riedel: > I thought iptables collects all fragments and reassembles the packet > before applying any rules? Or am I dead wrong here? Only if the ip_conntrack.o module is loaded. Cheers, Ralf -- Ralf Spenneberg RHCE, RHCX Book: Intrusion Detection für Linux Server http://www.spenneberg.com IPsec-Howto http://www.ipsec-howto.org Honeynet Project Mirror: http://honeynet.spenneberg.org