Hi, I want to drop all connections from/to subnet if I don't allow. For example, accept msnmessenger protocol with l7-filter and forward all 80 connections to content filtering software. Then I want to drop all connections. I write the rules and add the default action type to Drop. But now the clients cannot connect to msnmessenger. (I write the msnmessenger rule to FORWARD chain) Also, noone answer my previous mail, If I asked to wrong group or something wrong with the subject please remind me. Thanks Tolga __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com