Simplest way is to talk to your ISP, explain the situation and ask them to be more liberal in accepting connections from your webserver.
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
|