On Wednesday 18 February 2004 3:01 pm, Fabian Hartmann wrote: > > The telnet's being done from the box itself, telneting to the network ip > > (not loopback) of the box. Oh! I recommend not doing this, since it doesn't test the same bits of the ruleset as packets coming from another machine (which is what I assume you really want the rules to do). I did think you were testing from another machine. > > The same response occurs if the telnet is done from another box. In that case put a LOG rule just before the REJECT, as I suggested in my last posting, then we can see exactly what got REJECTed. Antony. -- If you want to be happy for an hour, get drunk. If you want to be happy for a year, get married. If you want to be happy for a lifetime, get a garden. Please reply to the list; please don't CC me.