Currently I'm using ip-masquerading to pass internet access to my local network. I assume that this must be possible, using ipchains... (and, btw, I don't mind reading the manual, but I tend to learn a _lot_ easier from example type things...) Can I only allow certain IP addresses on my network to get 'out'? or, better yet, allow activity on only certain ports to have outside access? Thanks in advance, Walt Materialists and madmen never have doubts. Gilbert Keith Chesterton ************ [EMAIL PROTECTED] http://www.linuxchix.org