On Wed, Nov 13, 2013 at 09:58:13AM -0800, Jim Mellander wrote: > For tcp, I tried the simpler > -A INPUT -d a.b.c.d/xx-p tcp -j REJECT --reject-with tcp-reset If this isn't intended for the firewall itself, you should not add this to the INPUT chain. Try FORWARD instead. Phil -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html