Hi Steve, The answer is really simple - yes and no ;) - Iptables can certainly understand single IP's - so if ethX:X has a static IP, you could just use that instead of the interface name.
However, if the interface doesn't have a static IP and you try to use the ethx:x syntax, you will get: Warning: weird character in interface `ethX:X' (No aliases, :, ! or *). Kind Regards, Scott Nursten S2S Limited http://s2s.ltd.uk [EMAIL PROTECTED]