On Sat, 2013-06-29 at 09:55 +0100, Andrew Beverley wrote: > You're marking the packets in POSTROUTING, but which time the routing > decision has already taken place. You'll need to mark them much earlier, > somewhere in PREROUTING. See this diagram for more information: http://upload.wikimedia.org/wikipedia/commons/3/37/Netfilter-packet-flow.svg You need to be marking packets before either of the "routing decision" boxes. -- To unsubscribe from this list: send the line "unsubscribe lartc" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html