The firewalling rules are 'matched' from top to bottom. Put you higher priotity rules nearer the top. Check out ipchains too as it is more versatile. There is an ipfwadm wrapper availble I believe, to help get you started quickly. Shaun -- It is? It was?