On Wed, 10 Mar 2004, Tim Neto wrote: > Break out the dstdomain to one (1) per ACL.
This would be a bad move. The dstdomain acl is explicitly designed for matching a list of domain names sharing the same property (i.e. not allowed etc..) Regards Henrik
