Still no dice. Not sure what I'm doing wrong. I've got logging to a box that has an external address (it's a web server). Logging trap debug. I set up Kiwi syslogd on the web server (windows 2000). Maybe I'm using this for the wrong reason, so let me give some background. I have a client who can't get to our website or send us email. Everyone else can (from the internet). For some reason, their traffic is being blocked or rejected. They can ping my router's external and internal interface, and traceroute. They can ping (after setting up a rule) my web server. When they try to get there via a browser, or send me email, it never shows up. It never shows up on my Raptor Firewall log. So I am back to looking at the router to see if logging would pick that up, since I can't confirm they're getting to my firewall. yes, I know a ping would establish THAT PROTOCOL can get there, but if their mail or http traffic is being blocked, it should at least show up on the firewall log as a rejected packet. No evidence, so I want to step back and check the router.