my friend Dan Lyke took one look at the Facebook post of my previous blog entry and immediately suspected a problem with port 53 over TCP. I checked and, sure enough, I had neglected to specifically allow client access to the domain service over TCP. fixed my iptables script and now I'm good to go. thanks Dan!

