i misread and applied the suggested changes to the "outside" interface but I've since taken it out because some websites weren't working after the change (ie hotmail/yahoo mail). in addition, I'm reluctant to apply this to the inside interface because I've got VOIP traffic coming through the inside interface from a remote site and I don't want to effect that.
So I guess I need to re-explain what it is I need?
1) I need to allow FTP to a new machine from outside in. This was pretty straight forward and I know what to do for this.
2) I need to allow all traffic back in that has originated from our LAN (all tcp, ip, and udp traffic). This is where I'm hung up currently.