> We definitely need something better manageable than iptables. The script > works, but IMHO iptables is hard to look through or manage. I updated our > task list to do this. If you don't like that idea, remove it from the task > list. If nobody says something, I will bring shorewall to the server and > migrate the iptables setup. Fine with me > Andi, do we have a direct console access (you know with firewall, networks > and ssh-thingies I kinda would like that for special setups :) ) we can reboot the machine into a rescue system from the hetzner Web console to fix things if they go wrong. I'm not in town this weekend so I can't do that, so better don't mess up this Weekend ;) For firewall stuff I usually set up a cron Job that completely flushes the tables every 20 minutes until I'm sure everything Works As it should. Andi -- splitbrain.org