In a HVM domain, the packets appear to come from the tapX interface, which isn''t automatically added to the firewall rules. Any suggestions for doing that? Also, it would be nice to be able to configure a chain to add the rule to, instead of it always being FORWARD. If I wrote a patch for this would it be considered? Thanks James _______________________________________________ Xen-users mailing list Xen-users@lists.xensource.com http://lists.xensource.com/xen-users