Hello, there is a problem in the outgoing firewall if it is used in mode 1. Packets are accepted from blue even if there is no rule for the MAC address of the sender. This problem has got a medium severity and does not affect any other configuration of the outgoing firewall and does not occur when no blue network interface exists. There is a fix available: http://git.ipfire.org/?p=people/ms/ipfire-2.x.git;a=commitdiff;h=78a14abf81e61ea4fc62d313dfd6779cda9421ae Please install and test. I am not going to repeat this request anymore. Michael