diff --git a/docs/FAQ.xml b/docs/FAQ.xml
index 25dcb2ab7..9b0fdb3ae 100644
--- a/docs/FAQ.xml
+++ b/docs/FAQ.xml
@@ -1040,6 +1040,11 @@ to debug/develop the newnat interface.
your firewall is responding to connection requests on those
ports.
+ If you would prefer to 'stealth' port 113, then copy
+ /usr/share/shorewall/action.Drop to
+ /etc/shorewall/ and modify the invocation of Auth
+ to Auth(DROP).
+
(FAQ 4a) I just ran an nmap UDP scan of my firewall and it
showed 100s of ports as open!!!!