$ 0 0 1) Netflow would well on the router.2) You could use PF as a passthough firewall before the gateways and run ntopng for a complete traffic view across the br0 port. Thanks,David.