hi, when i set the INPUT policy of DROP and then insert a rule -A INPUT -s lan-machine -j ACCEPT ,the lan machine normally must be able to ping the firewalled machine? with this syntax the -p option is default set to "all". so icmp is also under "all" to find ,or i am wrong?thanks for help, and much fun