My guess (based on recalling that PROTO 6 is tcp) is that someone trying dns zone transfers. You might want to run something like tcpdump or snort to capture some of the actual traffic to be sure. Michael At 11:24 2001-05-25 -0500, you wrote: ><snip traffic logging>