If the firewall is set up as statefull, with "ESTABLISHED,RELATED" on INPUT and FORWARD I.E. iptables -A INPUT -i $EXTIF -m state --state RELATED,ESTABLISHED -j ACCEPT then you must establish the connection and the ports being open or not is not really relevant. -- jludwig <wralphie@xxxxxxxxxxx>