Agreed, but output chain would work if the device is between internet and internal network. Mine is a Host based firewall. Tested Application Proxies, work fine in this case.I think I would go with it. Thanks, N -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html