@J65nko thanks again for your response...

* The 10.x networks are all /24 except 10.8 which is a /23
* I understand that these are defined - the file was hacked together before my time and I'm somewhat clueless
* I'm not sure what the purpose of
block out on $IntIFs from <LocalNetworks>

Again, I'm pretty junior on this stuff but have the task of making sure this works.. I would be willing to pay someone to actually do the work and implement. I would be the test monkey. Is this a possibility?
