Hi Where do I do iptables accounting? For example: If I have users on a private LAN surfing via a proxy on the firewall and I have web servers in a DMZ also being routed via the firewall, where do I put my accounting rules? In the FORWARD chain, or the INPUT chain, or both? Ray --