On Sun, Jul 18, 2004 at 04:10:51PM +0100, Antony Stone wrote: > You are missing either a "-s" source address or "-i" input interface > specification for the rule allowing access to the DMZ machine, or else you Which rule are you referring to exactly? > are missing either a "-d" destination address or "-o" output interface > specification for the rules allowing access from the LAN. Can you tell me something more specific. I am still unable to figure that if I have dropped all connections to outside, DMZ which is outside for the LAN how can connections be allowed for it? Do you want me to post the entire firewall file somwhere on net? Waiting eagerly for the reply. With warm regards, -Payal