Hello, I cannot stop getting these messages: Sep 17 06:54:48 nitro kernel: Shorewall:all2all:REJECT:IN= OUT=eth1 SRC=192.168.0.1 DST=192.168.0.131 LEN=68 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=53 DPT=1217 LEN=48 Though I have tried to allow this in the rules file. What am I missing? Basically I am running a caching dns server as well as a dhcp server on my firewall, so all local hosts are using the firewall for DNS resolution. Thanks, Alex@rettconsulting.com