On Mon, 2004-12-20 at 16:19, R. DuFresne wrote: > If I'm reading all this correctly then if set as both INPUT and FORWARD > rules the FORWARD rules would become redundant and never be hit as the > INPTU rules would be caught first and deal with what becomes of the > packets, yes? the FORWARD rules would never be hit because the packet never traverses the FORWARD chain. -j -- "What's the point of going out, we're just going to end up back here anyway?" --The Simpsons