> acl win1 dstdomain http://*.update.microsoft.com No, protocol shouldn't be in a dstdomain acl. The correct acl is: acl win1 dstdomain .update.microsoft.com If you want the protocol too you need the 'proto' acl type. Joost
> acl win1 dstdomain http://*.update.microsoft.com No, protocol shouldn't be in a dstdomain acl. The correct acl is: acl win1 dstdomain .update.microsoft.com If you want the protocol too you need the 'proto' acl type. Joost