On Monday 02 February 2004 5:02 pm, David C. Hart wrote: > Should this not reject echo requests? > > -A INPUT -p icmp -m icmp --icmp-type 0 -j REJECT --reject-with > icmp-net-prohibited > > It doesn't seem to work. Never mind that, you're not allowed to respond to ICMP packets with ICMP errors. See RFC792 page 1. Regards, Antony. -- Abandon hope, all ye who enter here. You'll feel much better about things once you do. Please reply to the list; please don't CC me.