>>>>> "bp" == Björn Persson <listor1.rombobeorn@xxxxxxxxx> writes: bp> As written, every incoming packet would be compared to those rules. You bp> couls however create a new chain, "blocked" say, and configure the log bp> watcher to add the rules to that chain. In the main "INPUT" chain you bp> would then have a rule to jump to the chain "blocked" only on connection bp> attempts to port 22. I see. Could someone more iptables-knowledgeable than I post some rules that accomplish what Björn has suggested? --- Vladimir -- Vladimir G. Ivanovic http://leonora.org/~vladimir Palo Alto, CA 94306 +1 650 678 8014