I'm wondering if I can define an access-list that will restrict a range of addresses within a subnet. As opposed to the entire subnet. I want to restrict some address from making queries to a specific zone. Or restrict them TO a zone. Is this possible? Thanks, kelly