You need to set up the ESTABLISHED,RELATED rule. Here is an example of a test firewall: http://installkernel.tripod.com/ipls -----Original Message----- From: netfilter-admin@xxxxxxxxxxxxxxxxxxx [mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx] On Behalf Of Peter Marshall Sent: Wednesday, June 30, 2004 9:06 AM To: netfilter Subject: traceroute Hi. I was wondering what I would need for rules to have traceroute work through my firewall. (I have a box behind the firewall trying to get out using traceroute). I have an allow established connections on my forwared chain, and I am allowing anything from the source IP of the box in question to leave ... It appears that the problem is on the packets comming back in .. but I am not sure what I have to do to fix it .... Thanks Peter