RobertKaucher wrote: » One thing to add to Dynamik's point... While a specific server migth only be used for one role, it does not mean that that is the only networking service on the server. How would you RDP to your DNS server if all ports responded with DNS? How would you drop a patch on your C$ share to install on your application server if all the ports were being directed to whatever application? How could you SSH to your apache server if there was an issue?