Ok let's add one more item... When adding a rule through the GUI it seems to want to change the source/dest zones away from what the user specifies.
I tried adding a rule for NNTP which went from lan -> wan. The gui goes off and changes source and destination zones. I finally got it working by changing the rules manually and manually reloading shorewall. -randy
