Can someone take a quick peek and tell me why I'm not getting through the firewall from the outside? Here is the ipchain. I just want to forward port 80 (www) requests to an internal host. Chain forward (policy DENY): target prot opt source destination ports ACCEPT tcp ------ 0.0.0.0/0 192.168.1.1 80 -> 80 MASQ all ------ 192.168.1.0/24 0.0.0.0/0 n/a When I try to lynx in from the U (to http://rephil.org or http://www.rephil.org) it tells me it cannot connect to host, but nslookup or dig both give the right spots for it, and I can ssh into the firewall from there. Hrm. TIA, Phil