The line that does the trick (and allows other servers to contact your server, note that without zone transfers) is access-list 100 permit udp 0.0.0.0 255.255.255.255 x.x.x.x 0.0.0.0 eq 53 Change x.x.x.x to be yor DNS server. Regards, Ariel -- Ariel Nowersztern Systems Programmer reln@cs.huji.ac.il Finger for GCode v3.1 Check out http://www.cs.huji.ac.il/~reln/ "The best way to keep one's word is not to give it." -- Napoleon Bonaparte