I think I have mis lead you. I have a SERVER publishing rule for the DNS server, just like on my win2k machine I have PROTOCOL rules for DNS query/lookup/xfer just like on my win2k machine. This is all that is required to make it work, but on win2k3 machine the only way an internet DNS server can query my DNS server (happens to sit in the lat) is if I add yet another PROTOCOL rule that allwos all protocols TO my DNS server's via client addresss set I created just for it only. Does that sound right? Sorry for all the confusion. -John