Hi, For the unbound daemon we can set: outgoing-port-permit: 32768-60999 outgoing-port-avoid: 0-32767 Is there a way for a libunbound context to put in the same limitations? We are seeing that sometimes libreswan's use of libunbound triggers selinux denials and I suspect it is due to the use of ephemeral ports. Paul