Duke wrote: > What's a good way to monitor BIND's traffic w/o using log files? Can it be > monitored at the TCP/IP level, by port? Yes, anything TCP or UDP with a source or destination port of 53 should be DNS traffic. - Kevin