Hello, My server is om Mandrake 10.1 eth0 is WAN with static IP connected to 512K DSL. eth1 is LAN - 192.168.0.0/24 , 192.168.21.0/24 I and doing a nat on eth0 as follows : # Generated by iptables-save v1.2.9 on Tue Apr 26 14:50:01 2005 *nat :OUTPUT ACCEPT [0:0] :PREROUTING ACCEPT [0:0] :POSTROUTING ACCEPT [0:0] -A POSTROUTING -o eth0 -j MASQUERADE What are the first rules that one would write.I mean how and where to start. What are the first rules that one would write. Do you start by blocking all ? Or allow all ? I am asking this just from the point of view of understanding the basic strategy. Basically clients will surf the net, send/recieve mails and MSN/yahoo chat. I would be using squid proxy. Thanks Varun