On Tue, 30 Oct 2001, dman wrote: (snip) > What is the solution? Is it a good idea to open up 'ident' in the > firewall? I think so, yes. Alternatively, can you have your firewall at least send an ICMP reply to say that the packet was dropped? (like the difference between DENY and REJECT with ipchains) -- Mark