Ramin Alidousti (ramin@cannon.eng.us.uu.net) wrote : >I wouldn't jump into conclusions yet. Can you play with the rules, eg, >remove >the firewalling rules, add an explicit "NEW/INVALID" rule to accept for >icmp... > >Ramin Hi Ramin, I even tried with a default ACCEPT policy on the FORWARD chain, and, as per your suggestion, with a NEW/INVALID state match. Didn't help though... -Filip