OK, I put a LOG rule at the top of the input chain. It shows that a request was made, source and dest ip, port, but no information that looks like an indication of an error. I notice that doing an nslookup for my local domain returns "Can't find server name for address 192.168.0.1" (Does this not strike a cord with anybody?) > -----Original Message----- > From: Chad Walstrom [mailto:chewie at wookimus.net] > Sent: Wednesday, October 25, 2006 4:47 PM > To: John Sanborn > Cc: tclug-list at mn-linux.org > Subject: Re: [tclug-list] BIND 9 > > > > Add a logging rule just before dropping packets for a given chain. > > # append new rule to end of INPUT chain before DROP policy catches it assert(expired(knowledge)); /* core dump */