I was just wondering if anyone here uses "return" in their rules .. I understand what it is for .. just wondering if it is efficient to use. ex. -A Forward -s 192.168.200.5 -o eth1 -j subchain1 -A Forward -s 192.168.200.0/24 -o eth1 -j subchain2 -A subchain1 -d 200.200.200.200 --dport 1234 -j ACCEPT -A subchain1 -d 200.200.300.300 --dport 4321 -j ACCEPT -A subchain1 -j RETURN -A subchain2 .......... blah blah blah .... Or would you just write the rules different ? Also, I was wondering is there a way to specify multiple source ip address ? ex -s 192.168.200.5, 192.168.200.20 ..... Thank you, Peter. Peter Marshall, BCS Network Administrator, CARIS 115 Waggoners Lane, Fredericton NB, E3B 2L4 CANADA Phone: (506) 458-8533 (Reception)