Hi, >>-A INPUT -i eth1 -p udp -m udp --dport 4500 -j ACCEPT >There is no such rule (given in the mail). There was one at the end of email in the iptables-save output. >Use `iptables-save -c`, it's much more complete and better to parse >because it does not try to make a pretty-print table that always wraps >in e-mail anyway. True ;-). Looks much better. Regards, Marek -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html