> It doesn't work like that. Read "man iptables" > again. Why your command > doesn't work is explained in the OWNER extension > section. > So, could it be that you are loading it in the wrong chain (not supported by the module) ? Indeed.... I missed the big capital letter words in the man page that <owner> is only valid in OUTPUT chain. > I don't see a netfilter connlimit kernel module, so > that could mean > it's neither built nor supported. In case the > extension is included > in the stock Linux kernel, that might be a package > bug. For the <connlimit> extension the kernel module isn't compiled in for FC2. Thanks all for helping out. Regards, DL __________________________________ TSUKAME EIKOU! KAGAYAKE EGAO! Yahoo! JAPAN JPC OFFICIAL INTERNET PORTAL SITE http://pr.mail.yahoo.co.jp/para/