I missed a couple of new features: 1) You can now use the "shorewall show zones" command to display the current contents of the zones. This is particularly useful if you use dynamic zones (DYNAMIC_ZONES=Yes in shorewall.conf). Example: foo:/etc/shorewall # shorewall show zones Shorewall-2.2.0-Beta7 Zones at foo - Sat Nov 27 9:18:05 PST 2004 loc eth0:192.168.1.0/24 eth1:1.2.3.4 net eth0:0.0.0.0/0 WiFi eth1:0.0.0.0/0 sec eth1:0.0.0.0/0 foo:/etc/shorewall # 2) Variable expansion may now be used with the INCLUDE directive Example: /etc/shorewall/params FILE=/etc/foo/bar Any other config file: INCLUDE $FILE -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key