This is more of a NF question but it is tightly related to LARTC as well. In the following example:
-t mangle -A PREROUTING -i eth0 -j MARK 0x1 .... -t mangle -A INPUT -i eth0 -j MARK 0x2
Since MARK is a non-terminatring target, what would be the resulting mark on a packet comming from the outside and destined for a local process?
The mark would be 0 until the packet hits the first rule. After that, it would be 1 through the remainder of the PREROUTING chains. After routing, it would pass to the INPUT chains where it would change to 2 when it hits the second rule and would remain 2 through the rest of the INPUT chains.
_______________________________________________ LARTC mailing list / LARTC@xxxxxxxxxxxxxxx http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/