Hello, I have a small problem. I need to log all the MAC addresses that come into a firewall from the outside world. The firewall is performing NAT. The problem is prerouting doesn't log the correct MAC address, Forward doesn't log a MAC address. The only one that seems to correctly log a MAC address is INPUT. However, I can't seem to write an INPUT rule that will then pass to a prerouting rule for NAT. Any ideas? Sincerely, Joshua Drake -- Co-Founder Command Prompt, Inc. The wheel's spinning but the hamster's dead