Is there any setting in the kernel or in iptables that will enable generation of a log of all SNAT mappings as they are created? The log should include the original source [IP, protocol, port] plus the mapped [IP, port]. Thanks, Alan Stern -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html