Hello List, i've a problem with my susefirewall 4.6 and my dmz. The Suse Version is 7.1. my configuration: FW_ROUTE = yes FW_MASQUERADE = yes FW_FORWARD_TCP="0/0,xxx.xxx.xxx.xx,80" I could not ping a webserver which is inside the dmz. The FW_ALLOW_PING_DMZ Setting is set to "yes". HTTP Access to the webserver is also not available. Pings from the inside (local net) and from outside (internet) are blocked. If the Firewall is stopped, the HTTP Access is available also pings from outside and inside. The /var/log/firewall says on http access from outside: May 16 19:49:10 dolly kernel: Packet log: input DENY eth1 PROTO=6 xxx.xxx.xxx.xxx:80 217.2.190.56:65386 L=48 S=0x00 I=16 F=0x4000 T=64 (#4) On ping command from outside: May 16 19:51:00 dolly kernel: Packet log: input DENY eth1 PROTO=1 xxx.xxx.xxx.xxx:0 217.2.190.56:0 L=60 S=0x10 I=24 F=0x0000 T=255 (#4) eth1 is the interface to the dmz, eth2 is the interface to the internet, eth0 is the interface to the local net. Does anybody know what goes wrong? I've tested version 4.2 and 4.3 with the same configuration before, no change. Best Regards Andreas Müller