Linux, iptables and logging masquerated connections

http://serverfault.com – I'm setting up a linux box to masquerade LAN connections to the internet using iptables. System is pretty much set up like: +------------+ +----------------+ |Some host in| |Masquerador | +--------+ |my lan |---|WAN: dynamic |---|internet| | | |LAN:| +--------+ +------------+ +----------------+ Masquerading itself was pretty straightforward: # flush iptables -t nat -F # and go iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE but how do I log the masquerated connections? I tried # new chain for logging iptables -N LOGMASQ -t nat # tar (HowTos)