Actually what he said is that his POLICY is set top drop, not any rule. Which is a perfectly ok thing to do. It actually should work. I'm betting my money on missing an ACCEPT in the OUTPUT rule chain.
Andres -- http://sql.nu/ Matias Lambert said: > Hi, > I think that your problem can be that you have the DROP rule before the > ACCEPT rule in your INPUT chain, if you put the command in the same > order that you email us, the packet will be droped. <snip> > inflo wrote: > >> hi, when i set the INPUT policy of DROP and then insert a rule -A >> INPUT -s lan-machine -j ACCEPT <snip>

