On Wednesday 15 June 2005 08:01, Mohamed Nassih wrote: > it does not work, > > please help Sorry, no, but I will tell you why. OUTPUT restrictions are hard to do. I don't mess with them myself, and it's possible I have a much greater understanding of firewalling than you do. Of course OUTPUT only affects locally-generated packets, not the MASQUERADE ones from your local network, so that may not be your issue. What you want to do is probably covered in the simple examples in the Packet Filtering and NAT HOWTOs. Read them. If you have done so you can come up with a more specific statement of problem and question than "it does not work, please help." Then if I have time and know the answer I might help. Guido pointed out a definite show-stopping typo in your script, BTW. There will be no packet forwarding with a typo like that (unless it was turned on in some other way, such as the distro's sysctl interface.) -- mail to this address is discarded unless "/dev/rob0" or "not-spam" is in Subject: header