> The ping thing is not exactly a simple issue although I'm sure it is > from a perspective that doesn't involve thinking about it too hard. > I didn't say it was a simple issue. You asked, I answered. A year ago, iptables did everything, with no problems, ipf had those problems I mentioned. Telling management "wait a year till ipf works" wasn't an option. Adam