ok, I got most of the basics down. when i want to deny an ip or all of an ip block (last numbers only) I can do: iptables -A INPUT -s xxx.yyy.zzz.0/24 -j DROP and it takes care of the entire ip block. However, I want to block entire ranges hwere I have XX.YY.0.0 between xx.yy.0.0 and xx.yy.255.255. whats the netmask notation for this? also, whats the notation if I want to block a partial range on the last digets (llike xxx.yyy.zzz.aaa-bbb where aaa= low end and bbb= high end)? some thinsg are just not explained in the iptables howto here are the addresses I really wish to block: 65.192.* 63.64.* 209.244.* if someone would be so kind as to help me figure out the netmask notations on the above, I would greatly appreciate it. Thanks Technomage