Ok -- I''ve recovered from the brain cramp that resulted in the hack that I sent out earlier (I plead guilty to the charge of "Watching the Super Bowl and designing the change at the same time"). The version in CVS (Shorewall project) should fix the VLAN problem. -Tom Tuomo -- the ''large complex change'' turned out to be 8 lines :-) -- Tom Eastep \ Shorewall - iptables made easy Shoreline, \ http://www.shorewall.net Washington USA \ teastep@shorewall.net