On Saturday 13 March 2004 5:41 pm, Vlad H. wrote: > Hello to all, > > I have to give internet access to a small group of users from a local > network. Internet interface is eth0 and local lan interface is eth1. I > guess these rules are ok for my intention: > > But I recently found out that mac address can be changed. So, I need a > third security identifier for iptables or any other solution to increase > security. Any clues on this? thx. What is your concern? What activity are you trying to prevent? What activity are you trying to allow (ie: what sort of access to the Internet do you want to allow people - mail? web? ftp? telnet? ssh? etc...) Antony. -- Normal people think "If it ain't broke, don't fix it". Engineers think "If it ain't broke, it doesn't have enough features yet". Please reply to the list; please don't CC me.