Gogousa wrote: » You should put the second one on top of the list. Think like the packet and a list to do. If something wants to go out, it reads the first line, if it does not apply it goes to the second line, and this goes on and on until it finds something that apply to him, and thats it (the packet is out). If it gets to the end of the list and nothing apply to it, it is discarted. So, the policies should go from specific on the top (like your example, one server-one port) to general at the end. hope this help good luck