Hi, I have a little question with two negatived parameters in one rule. I create a rule, which should only match if source and destination are not the given. I think that it is easy and try the following rule: iptables -A FORWARD -s ! host1 -d ! host2 -j ACCEPT But with this rule pakets from host1 to host3 (or from host2 to host3) were not affected. It seems like the logical combination is OR and not AND unlike the not negatived rule. I think that the rule is logical right. Is it a little bug or have I misunderstood something? I used the version 1.2.11 with kernel 2.4.26. Markus -- NEU: Bis zu 10 GB Speicher für e-mails & Dateien! 1 GB bereits bei GMX FreeMail http://www.gmx.net/de/go/mail