On Monday 10 November 2003 9:14 am, Marc Lucke wrote: > Hi, > > Do the iptables counters include layer 2 ethernet packet headers? If > so, how much traffic is this - is it a set amount? No, because you may not be using ethernet. Netfilter can be used for packets across ethernet, 802.11, PPP modems - all sorts of network transports. Packet and byte counters in netfilter are IP (OSI layer 3) and upwards. You can check this easily by creating a rule matching something specific (eg ping packets), send a known amount of traffic through the box (or measure it with a packet sniffer / protocol analyser such as ethereal, which will give you a detailed view of the contents of the packets), and then check what the counters say. Antony -- Anything that improbable is effectively impossible. - Murray Gell-Mann, Nobel Prizewinner in Physics Please reply to the list; please don't CC me.