zhang888 1066 Posted ... Yes this is possible with --lport directive.However this is not very recommended, from many perspectives, and you will not gain any extra securityfrom this setting. You should look into hardening your security on the network layer, not the transport layer.So you will have a better solution dropping all connections to any destination except your entry IP. Specifying a local port is not advisable for privacy reasons as well. If your ISP provides an IP addressbehind NAT, they share the same IP address among many subsribers without virtually knowning who iswho. By using specific patterns and hard coded ports you are losing this little benefit. Quote Hide zhang888's signature Hide all signatures Occasional moderator, sometimes BOFH. Opinions are my own, except when my wife disagrees. Share this post Link to post