On Tue, 30 Aug 2005, foren titze wrote: > ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp > dpt:443 > ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp > dpt:220 > MY_REJECT all -- 0.0.0.0/0 0.0.0.0/0 > ACCEPT esp -- 195.xxx.xxx.21 0.0.0.0/0 That ACCEPT rule will never be reached. Paul