On Sun, 2005-03-20 at 16:40, Georgi Alexandrov wrote: > Use the ULOG (userspace logging) target and the ulogd deamon. That way > you may specify logging to a particular file (supports sql logging too). > More at: http://iptables-tutorial.frozentux.net/iptables-tutorial.html in addition to the ULOG target/ulogd solution (which is the easier way to go), you could also use syslog-ng as your syslog daemon and use its filtering capabilities to say, dump all logs entries with the string "FIREWALL" into /var/log/firewall. -j -- "Asleep at the switch? I wasn't asleep, I was drunk!" --The Simpsons