Some quick math show that roughly 80% of your total traffic is trappedby that rule. Ouch! Also, do you really want your default policy to beaccept? It looks like you had 736 Mbytes go to some other (unknown?)destination on your firewall box. Jeff You know I had never noticed that. I rely on my rule and statematching to DROP connecctions I do not want. It may be possible that some of the protocols I have not accounted for are coming through? What do you thaink guys? And thanks Jeff for pointing that out! SBlaze. ===== In the absence of order there will be chaos. __________________________________ Do you Yahoo!? The New Yahoo! Shopping - with improved product search http://shopping.yahoo.com