I know I can use ACLs to setup what hosts can AXFR with allow-transfer, but I'm wondering if there is a way to only allow transfers to hosts specified as NS in the zone. That would avoid having to update the bind conf file if a zone's NS records change. Is that possible in Bind9? -- Bill Moseley moseley@hank.org