On Mon, 2003-02-10 at 22:32, jpiszcz wrote: > However, when I run tcpdump, I can clearly see these are not getting > dropped or logged by the kernel. Could your problem actually be a testing flaw? tcpdump sees firewalled packets since it works at packet level, below the IP stack. -- // Gianni Tedesco (gianni at scaramanga dot co dot uk) lynx --source www.scaramanga.co.uk/gianni-at-ecsc.asc | gpg --import 8646BE7D: 6D9F 2287 870E A2C9 8F60 3A3C 91B5 7669 8646 BE7D