--> Thanks Terr. In answer to your question, there are only the heavy packet flows on those two ports (for TPF: persfw.exe and pfwadmin.exe , in and out) EVEN WHEN ONLINE. Since the heavy flows were evident during the previous firewall installation (ZoneAlarmPro), I am guessing that they too were using the ZoneAlarm in-and-out ports, for the corresponding ZoneAlarm Exe's. I'm not sure if they are evidence of a problem or just a harmless glitch.
--> Since it happens offline, I am guessing no real trouble exists, but this guess is based on my present knowledge (not much).
--> Just a thought, is there a way i can discern what information is IN the packets?




