Thanks for everyone's help. Gonna test my script some more, document my settings in a notebook, and do it all over again for the production install.
When you're done and you have the thing working well with your current toolset (if it ain't broke, don't fix it), you may want to try to repeat the task using Shorewall. I highly recommend it as a more flexible, powerful tool which I just happen to find also easier to use. Used it on over 50 systems so far, I'd guess.
Cheers,
-- Rodolfo J. Paiz rpaiz@xxxxxxxxxxxxxx http://www.simpaticus.com