I just noticed that when configuring firewall rules for an AWS instance, if "DNS" is chosen then the (only) protocol automagically filled in is UDP. To get TCP, you have to create a custom TCP rule. When you save, the UDP one gets saved as "DNS", the TCP one stays "custom TCP rule". -- Fred Morris