On Red Hat, you can either edit /etc/init.d/iptables or /etc/sysconfig/iptables. The former can be overwritten when upgrading iptables package, the later can be overwritten with some temporary configuration on system reboots (depending on configuraiton) or when somebody calls init.d script with "save" argument by mistake (making it "machine generated file", while it should be "administrator generated configuration file").
So, the question is, how do you usually do it?
-- Aleksandar Milivojevic <amilivojevic@xxxxxx> Pollard Banknote Limited Systems Administrator 1499 Buffalo Place Tel: (204) 474-2323 ext 276 Winnipeg, MB R3T 1L7