The rule structure for handling complex zones (those requiring entries in /etc/shorewall/hosts) has been improved through the addition of an intermediate forwarding chain. For those who have such zones, this change can substantiallyreduce the number of rules in the <interface>_fwd chains. -Tom -- Tom Eastep \ Shorewall - iptables made easy Shoreline, \ http://shorewall.sf.net Washington USA \ teastep@shorewall.net