Hallo David, On Wed, 29 Oct 2003 14:19:55 -0500 "David C. Hart" <DCH@xxxxxxxxxxx> wrote: [...] > 4. I would rather use the FILTER table for the refused connections to > reject rather than drop. I'm sure that it's simple but I just don't get > it. This would depend upon the filter table rules following the NAT > table rules. Where is this order established? Take a look at http://iptables-tutorial.frozentux.net/iptables-tutorial.html#TRAVERSINGOFTABLES -- Gruß Jörg -- Jörg Schütter http://www.lug-untermain.de/ joerg@xxxxxxxxxxxxx http://www.schuetter.org/joerg/ ICQ: 298982789 http://mypenguin.bei.t-online.de/