OK, I put a LOG rule at the top of the input chain. It shows that a request
was made, source and dest ip, port, but no information that looks like an
indication of an error.

I notice that doing an nslookup for my local domain returns "Can't find
server name for address 192.168.0.1" (Does this not strike a cord with
anybody?)

> -----Original Message-----
> From: Chad Walstrom [mailto:chewie at wookimus.net]
> Sent: Wednesday, October 25, 2006 4:47 PM
> To: John Sanborn
> Cc: tclug-list at mn-linux.org
> Subject: Re: [tclug-list] BIND 9
> 
> > > Add a logging rule just before dropping packets for a given chain.
> 
> # append new rule to end of INPUT chain before DROP policy catches it
assert(expired(knowledge)); /* core dump */