> > I've played around with this some more, and it would appear that the > > policing works fine, it's just getting the marks detected > that's a problem. > > There is a Kernel config option near policer called packet > action if you > select it, policer will be before PREROUTING if it is unselected then > you will be able to select the old policer, which is after PREROUTING. *thankyou*! it works brilliantly, now. (Well, the marks are getting matched, at least - I'm still tweaking the settings.) Never realized that was an issue: I suspected it might be a kernel config issue, so I went through and simply enabled everything related to these network-ish functions. Obviously, brute force and ignorance isn't the best option all the time. ;-) Thanks heaps for your help. Cheers, Michael _______________________________________________ LARTC mailing list LARTC@xxxxxxxxxxxxxxx http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc