On Monday 04 July 2005 05:47, Christoph Georgi wrote: > make the default policy of the incoming chain (input) drop, but allow > established and related traffic, and allow all outgoing traffic by > setting the default policy to allow for the output chain (although > it's adviced to specify the outgoing traffic further..) Why, and by whom, is that advised? > umar draz wrote: > > [snip] > > how i can do it All this is clearly described in the Packet Filtering HOWTO. Or you can use one of many ready-made scripts without bothering to learn how firewalls work. -- mail to this address is discarded unless "/dev/rob0" or "not-spam" is in Subject: header