hi Martin, I found almost the same except that my ssh-packets didn't have their TOS-value set. > So, one *should* be able to do something like this: > > # iptables -t filter -A FORWARD -m tos --tos 0x08 -j scpchain > # iptables -t filter -A FORWARD -m tos --tos 0x10 -j sshchain That's almost the same idea as in the "actual script" from the HOWTO. So it seems my ssh-client doesn't like to set tos-values :o > http://iptables-tutorial.frozentux.net/iptables-tutorial.html *bookmarked* ;) greetings Sebastian -- Sebastian 'spax' Pape | "Things should be as simple as possible, but mailto: sebastian@p-a-p-e.de | not simpler." -- Albert Einstein gpg: http://p-a-p-e.de/gpg.asc | --- Do you want to know more? http://www.p-a-p-e.de/ --- _______________________________________________ LARTC mailing list / LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/