I noticed a cut and paste error in the zone files comment for the
'Limit' rules - here's the diff with what I believe is correct:

[snake fiaif]# diff -u zone.ext.orig zone.ext
--- zone.ext.orig	2003-01-18 19:58:46.000000000 -0500
+++ zone.ext	2003-01-18 19:58:58.000000000 -0500
@@ -97,7 +97,7 @@
 ## Limit new packets.
-## Use MARK[N]="<zone|ALL> <mark number> <protocol [port<:port>[<,port>[:port]]*]> <ip[/mask]=>ip[/mask]>"
+## Use: LIMIT_XXX="<zone> <policy> <limit> <burst> <protocol [port<:port>[<,port>[:port]]*]> <ip[/mask]=>ip[/mask]>
 ## Where:
 ##   ZONE     : Is the zone from which the packet originates. This can be this zone itself.
 ##   POLICY   : Is waht to do with the packet: ACCEPT|REJECT|DROP


