From: Francis Cianfrocca Date: 2006-10-04T13:05:35+09:00 Subject: Re: NET::HTTP behind a firewall? ------=_Part_17332_3517763.1159934731231 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline On 10/3/06, Joe Regular wrote: > > and here is the output of iptables -L... DROP tcp -- anywhere anywhere tcp flags:FIN,SYN/FIN,SYN Take a look at that rule, near the top of the INPUT chain. That tells me that you won't be able to accept TCP connections because you've turned down any packet with the SYN flag set. Have you tried adding some LOG rules to your config so you can tell what's going on? I don't know much about "KISS" but I think with a bit of research you can write yourself a far simpler iptables config that will be just as secure as this purportedly is. ------=_Part_17332_3517763.1159934731231--