I, personally, use FireHOL and I'm more satisfied with it (=simpler) than I was with Shorewall. YMMV.> Here it goes. I wondered about a clever way to load my iptables > ruleset via init.d's script. Surprisingly, I didn't find any with > Debian. I didn't search that much though. Have a look at Shorewall -- it does similar things to what you're proposing, and is already written. There's probably also a lot of other firewall maintenance systems with similar methods. - Matt
-- HTH, Massa