Thanks. This allows private access on both ports, however, I still can't connect to the machine from outside (=public access) on 23. I assume this is due to ipchains not allowing connections on that port. at least, ipchains -L doesn't list port 23 as accepted. I've tried to read /etc/rc.d/init.d/ipchains, but it only appears to load /etc/sysconfig/ipchains, which on my system doesn't exist. Anything I'm missing here - there must be a place somewhere where I can find & amend the firewall rules, or am I totally wrong?