This is just a role up of a fix for DNAT with the source zone = $FW (fw). Unless you have such rules, there is absolutely no need to upgrade. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@shorewall.net