I would sniff the traffic and see what port it is communication on and then do a block on the output chain for those ports. Hugh "Stephen Smith" > > I am looking for the best way to block this > before it gets blocked by the DNS. > > > Any Ideas? > > Stephen