Is there any reason why the default initial timeout for keep alive packets needs to be as long as two hours? This period causes the dynamic rules in my firewall filter to timeout. Is there a major objection to reducing the default idle time to say 3 to 5 minutes? Simon Walton