    > There are several computers(1....N) connected to the SERVER.
    > I'm trying to put iptables instead of ipchains in my SERVER.
    > On the SERVER I'm running Squid as a proxy server.
    > Now, I want some computers to access internet and some don't.The
    > pc's belonging to the persons who have an account in the proxy are to
    > be allowed to go through.So, I tried the below configuration in my
    > iptables to avoid Ip-Spoofing inside my own network.
    > *filter
    > :INPUT ACCEPT [255:28806]
    > :FORWARD DROP [0:0]
    > :OUTPUT ACCEPT [13:972]

    Use the redirection / access controls in squid - much easier - also you
    won't have to rewrite your rules every time the firewall / network changes.

    If your sure that your users are smart enough to spoof an ip address but
    dumb enough not change the MAC address too, then try arpwatch.



