On Thu, 17 Oct 2002, Walter Haidinger wrote: > Marking packets with iptables -t mangle works too! Masqueraded packets > have to be marked in the PREROUTING chain, locally generated packets in > the OUTPUT chain of the mangle table. Only for the record: The above is true for locally (i.e. on the router itself) generated data. Packets _not_ originating from the router have to be marked in the FORWARD chain of the mangle table. Walter _______________________________________________ LARTC mailing list / LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/