10/15 Hello Pete Nesbitt, Thank You for the response. The gateway's external interface is 'eth1'. The internal interface is 'eth0'. Hence you interpretation is right. a) Log for testing purpose, all syslog traffic from gateway to logserver going out through *eth0* to inside. Hence the rule is in the OUTPUT chain as the traffic outputs to *eth0* to reach the internal network. b) I know the second rule is wrong. I wanted a rule that logs all traffic inside but for udp 514 traffic as it is dealt in the earlier rule. Thanks. Menon -- redhat-list mailing list unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe https://www.redhat.com/mailman/listinfo/redhat-list