Hi. I've used tcpdump to dump our network traffic. I used 'tcpdump -q -n -i eth0'. I've thought about writing a program that would record the foreign hosts, and another program that would puruse the output of the second program to display what went on. About ipcains... my boss had me copy the inetd.conf and hosts.allow from our first nameserver to the three new boxes I just built. We are using Tcp_Wrappers and Bind 8. I'm not familiar with IP:Acounting or netflow. Is there a place that I could learn about these programs? Thanks for your help and efforts, lee lee@ricis.com - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.rutgers.edu