James P. Kinney III wrote: >On Sun, 2006-06-25 at 08:23 -0600, JK wrote: > > > >>#/usr/sbin/iptables -I INPUT -p tcp ! -s 218.23.45.2 --dport 80 -j DROP >> >> > >/usr/sbin/iptables -I INPUT -p tcp -s ! 218.23.45.2 --dport -j DROP > >More better. if source is NOT foo... > > Blah. I was thinking of 'find' syntax, where the negation precedes the option. That'll teach me to be a smarty-pants. -- JK