chetanm wrote: » you can try this command ip inspect name FWOUT tcp ip inspect name FWOUT udp ip inspect name FWOUT icmp ip inspect name FWOUT ftp //ftp is important to inspect because it can use a secondary port initiated from the outside ip access-list extended INBOUND deny ip any any int fa0/0 description OUTSIDE ip access-group INBOUND in ip inpsect FWOUT out ip address 1.1.1.1 255.255.255.0 ip nat outside int fa0/1 description INSIDE ip address 192.168.0.1 255.255.255.0 ip nat inside