This is a role up of Roger Aich''s fix for DNAT rules that exclude a sub-zone (e.g., DNAT z1!z2 ...). If you don''t need those types of rules then there is no need to upgrade to this version. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://shorewall.sf.net ICQ: #60745924 \ teastep@shorewall.net