On Thursday 27 November 2003 12:48 pm, sc2@xxxxxx wrote: > > So "iptables -I FORWARD -m state --state >ESTABLISHED,RELATED -j ACCEPT" > > might be a good idea. > > i should include this ? This will alloow the reply packets pack again - if you don't have this, you need a specific rule to allow those the same as you have a specific rule to allow the original packets. Don't forget communications go both ways through a firewall :) > b.) the port / service is a udp/tcp , port of a half - life game server, so > the clients are not on the same subnet > they are connecting to x.24.51 > and should FW to .24.58: Does halflife work through NAT? I don't know (maybe someone else here does), but you should be aware that there are some protocols which just work through NAT, some which are a bit of a challenge, and some which won't work at all. I don't know which group halflife falls into. Antony. -- Most people have more than the average number of legs. Please reply to the list; please don't CC me.