I have default drop on all INPUT,OUTPUT,FORWARD iptables chains.What if i default drop also the prerouting chain in the iptables script and than accepting connections for services on my inside lan pcs ? Thanks ! Gabriele