As promised, 1.3.1 is now available: 1. The handling of "all <zone> CONTINUE" policies has been corrected. Use of these policies greatly simplifies whitelisting and other nested zone configuration. 2. Added an /etc/shorewall/rfc1918 configuration file for defining the behavior of the ''norfc1918'' interface option. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@shorewall.net