Hi Mike, To be honest, I don't like the tcp/ip filtering in win2k. It gave me problems with udp traffic, and it cant block icmp traffic properly.
I prefer using ipsecpol to create a good policy. it looks like a mini-personal-firewall. simply use something like: ipsecpol -w REG -p "DNSPOL" -o ipsecpol -x -w REG -p "DNSPOL" -r "BlockAll" -n BLOCK -f 0=*::* ipsecpol -x -w REG -p "DNSPOL" -r "AllowICMP" -n PASS -f 0=*:*:ICMP ipsecpol -x -w REG -p "DNSPOL" -r "AllowDNS" -n PASS -f *+0:53:UDP you can find ipsecpol.exe + help in the resource kit of win2k --type_o --------------------------------------------------------------------------- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, while InStat has confirmed Neoteris as the leader in marketshare. Find out why, and see how you can get plug-n-play secure remote access in about an hour, with no client, server changes, or ongoing maintenance. Visit us at: http://www.neoteris.com/promos/sf-6-9.htm ----------------------------------------------------------------------------