Hello All, I have setup a bridging firewall. I want to drop packets on the external interface, which have source addresses on my internal network. However, the firewall/bridge sits between my T1 router and the rest of my LAN. Is there a way to drop the packets mentioned previously, but allow the router? I guess a rule could be created that uses the routers mac address as a match. I've been playing around with this, but I'm not getting the result I want. I could sure use some advice on this. [ LAN xx.xx.xx.0/24 ]<==>[ bridge/firewall ]<==>[ router xx.xx.xx.254/24 ] Thanks in advance, Gerry --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.576 / Virus Database: 365 - Release Date: 1/30/2004