Hi, I'm trying to set some rules for an output firewall, denying access to some sites. My linux box acts as a ip-masq for the internal sub-net of Windows machines. It has 3 cards: one for output to Internet, with a valid IP address and 2 for the internal sub-net. IP-Masq is working OK; all machines can telnet, browse, ftp, etc to external servers on Internet, being masquerade with the Linux IP. I'm using this sintax: # ipfwadm -O -a deny -S 0.0.0.0/0 -D some.site.denied/0
but isn't working, since I can connect the denied site from a inside machine. What is wrong? Does I need some other software in order to have an Output Firewall? Thanks, []s, Mario O.de Menezes "Many are the plans in a man's heart, but IPEN-CNEN/SP is the Lord's purpose that prevails" http://curiango.ipen.br/~mario Prov. 19.21 -- TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to [EMAIL PROTECTED] . Trouble? e-mail to [EMAIL PROTECTED] .