Hi, I am rephrasing my last question with better words and more information. My firewall config (simple) is kept at, http://payal.staticky.com/tables.txt My problem is simple I have a DMZ machine where mail server is hosted. Its apache (needed for webmail) can be accessed from outside world by http://<ext IP>. But if I give http://<ext IP> from a LAN machine I cannot access it. Upon further investigation I found that port 25 and 110 can be accessed from LAN but not from the gateway (firewall) machine. Therefore, since this machine is also a simple squid proxy to LAN, I cannot access webmail thru' LAN. Now, if someone can help me in access those services from the firewall machine itself, it will be great. I have blocked access to port 80 -d 0/0 from LAN and allow access only through squid. If you need more information, do tell. Waiting eagerly for any inputs. With warm regards, -Payal