$ 0 0 Instead of a firewall rule, you need a blackhole DNAT. See #2 in Rulz for an explanation. Cheers - Bob