Ok, further testing is showing that DNS is breaking with UT in place. I can ping 4.2.2.1 from UT and from a PC inside on the network, but even with all rack units disabled, DNS is not working. I noticed that the Attack module seemed to be blocking lots of stuff, so I disabled it. I have no idea what that thing was doing.
Regardless, with UT in place, DNS does not work. Our PCs query an internal DNS server which in turn queries an external server. That seems to be breaking with UT in place.
Any thoughts?