YOu must have to output chain also. Regards Dharmendra.T Linux Security Expert On Wed, 2002-12-25 at 17:02, paras wrote: > hi all > > > I have default policy to DROP on one machine. but i want the web server (80) > to be accessed from the internet but it is not working with the following > script. help plz. > > iptables -P INPUT DROP > iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT > iptables -A INPUT -p tcp --dport 80 -m state --state NEW -j ACCEPT > > > Thanks > Paras. > > ------------------------------------------------------------------------ > To unsubscribe email security-discuss-request@linuxsecurity.com > with "unsubscribe" in the subject of the message. > ------------------------------------------------------------------------ To unsubscribe email security-discuss-request@linuxsecurity.com with "unsubscribe" in the subject of the message.