John Anderson has pointed out that Upgrade Issues bullet #7 seemingly conflicts with the second item 4 in the Release Notes and on the Home Page. There is a typo in Bullet #7 -- "not" should be "now". The bullet should read: Late-arriving DNS replies are now dropped by default; there is no need for your own /etc/shorewall/common file simply to avoid logging these packets. -Tom -- Tom Eastep \ Shorewall - iptables made easy Shoreline, \ http://shorewall.sf.net Washington USA \ teastep@shorewall.net