This is not an answer to your question, but it's somewhat appropriate here: There is a great iptables preprocessor called Shoreline Firewall (http://shorewall.net). I can't recommend it highly enough - it makes complicated iptables easy. Try it out sometime! Paul