In Chapter 24 Firewalls: Section 24.6.5.7: Example ruleset #2: $cmd 020 $skip tcp from any to x.x.x.x 53 out via $pif setup keep-state ^^^ ^^^^^ DNS uses UDP, setup is inapplicable to UDP The line should read: $cmd 020 $skip udp from any to x.x.x.x 53 out via $pif keep-state Graham Dresch Development Eng SPC International