> Or, you can do what I do, and IP-Chains everything off except !-y (not > syn) tcp packets or portforwards. ;-) Yeah, I suppose you should allow > syn on ssh ;-) Probably http too. ;-) Got an example... :)