On Monday 11 September 2006 18:57, Herbert Poetzl wrote: > I completely agree here, we need a separate namespace > for that, so that we can combine isolation and virtualization > as needed, unless the bind restrictions can be completely > expressed with an additional mangle or filter table (as > was suggested) iptables are designed for packet flow decisions and filtering, it has nothing common with bind restrictions. So, it may be only packet flow scheduling/filtering, but it will not help to resolve bind-time IP conflicts. -- Thanks, Dmitry.