> I would like to point out that it has unfettered access due to the > defeault allow all LAN rule. Changing this will allow finer grained > control.
Yep, sorry I meant to include that point. I tested with a finer tuned set of LAN rules and, as you might expect, it works just fine.
