I have installed the snort woody package. I have also iptables active as firewall. I have noticed that Debian starts snort with -D and -b and -i eth0 options. I was wondering where snort is located in this fashion: behind OR beyond the firewall ? -- saluti, Mauro On this machine no Windows system survives and LINUX POWER reigns UNLIMITED.