I cannot figure this out. Our server - running IPTables - has very few ports open to input and the default is Drop. While a substantial number of 139 and 445 packets show up in the log as rejected, I am seeing a few attempts to connect to Samba in the log. These are identified by WAN IPs so they are not spoofing localhost or a LAN IP. I also have INVALID and fragmented packets rejected so that path is closed. So far, nobody has actually gained access, yet it is disconcerting. Any ideas how these are getting past the firewall? -- David Cary Hart Hart's PGP key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x58A60BB1