On Wednesday 13 November 2002 1:24 pm, Raymond Leach wrote: > Hi > > Where do I do iptables accounting? > > For example: If I have users on a private LAN surfing via a proxy on the > firewall and I have web servers in a DMZ also being routed via the > firewall, where do I put my accounting rules? In the FORWARD chain, or > the INPUT chain, or both? Packets being routed through your firewall go through the FORWARD chain and not through the INPUT chain. Packets going to a proxy application running on your firewall go through the INPUT chain and not the FORWARD chain. Antony. -- Anything that improbable is effectively impossible. - Murray Gell-Mann, Nobel Prizewinner in Physics