On Tue, 2008-03-04 at 11:47 +1300, Amos Jeffries wrote: > I can see nothing about "cache_peer_access allow all" in there. Is it > because it started that way or is it really missing? Default is allow all unless you say something else.. I would think the problem is a missing never_direct, or perhaps some acl depending on full-blown DNS access... i.e. a dst acl..