From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Ming-Ching Tiew" Date: Wed, 05 Sep 2007 04:00:46 +0000 Subject: Re: [LARTC] NAT-aware traffic analysis Message-Id: <011501c7ef71$56d6f760$0100a8c0@MingChing> List-Id: References: <00af01c7ef6a$1c8a3560$0100a8c0@MingChing> In-Reply-To: <00af01c7ef6a$1c8a3560$0100a8c0@MingChing> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: lartc@vger.kernel.org From: "Salim S I" > A different approach is to use iptables counters in FORWARD chain (-s > $CLIENT_IP -i eth0 -o ! eth0). That would require a rule for each user. > > Well sort of theoretically possible but bad in pratice. If I have 300 internal users, I will have to create 300 iptable rules. Then if I want to analyse based on sport or dport, you can imagine the number of rules will be quite many. Anyone has other suggestions ? _______________________________________________ LARTC mailing list LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc