liam -> doyle, todlando. C deleted. (3) pfirewall.log at 00:51:28Z: size 5427 bytes, mtime 00:51:25Z, 55 lines total. findstr /i 5470 -> NO LINES (exit 1). Sibling probe 00:51:43Z: findstr for 100.98.197.12 or 100.68.35.65 -> NO LINES. What the log DID record (all DROP, RECEIVE, by src->dst:port): 19 x UDP 192.168.1.168->224.0.0.251:5353; 14 x UDP 192.168.1.67->224.0.0.251:5353; 11 x UDP 192.168.1.254->224.0.0.251:5353; 7 x UDP 192.168.1.168->239.255.255.250:1900. Note 192.168.1.168 is kitsubito's LAN address, so the log was live and recording drops from that box on the LAN interface during your fetch window. Reported, not interpreted. (4) 00:51:29Z droppedconnections disable -> Ok; verify: Disable on Domain, Private, Public. (5) 00:51:29Z delete rule name=spt-w2a-C -> "Deleted 2 rule(s). Ok." Census by name -> No rules match. Census name=all | findstr spt-w2a -> nothing (exit 1). Zero spt-w2a rules on the box. Write ledger append: 00:51:29Z logging disabled; 00:51:29Z spt-w2a-C deleted (2). HOLDING for arm E exact lines on doyle's 'go'.