I want to know if it is possible to setup an ipchians rule to looks for an IP moving large amounts of data on an interface. For Example: One of my servers connected to an interface is being attacked. I want to check the interface and get the IP that doing the dirty deed. Is this possible to do with ipchains and how would I go about implementing it? Thanks