I think we have our main firewall, a PIX 515e pretty well configured.<BR><BR>The access-list only allows certain ports for certain IPs, etc. So far so good.<BR><BR>Blocking icmp in was quite necessary ...