On Dec 4 2007 10:17, Patrick McHardy wrote: > > I still don't see why you can't keep --set-mark and add new options > --and-mark, --xor-mark, ... > -j CONNMARK --xor-mark 0x01 -j CONNMARK --and-mark 0xffffffdf -j CONNMARK --or-mark 0x400 I would prefer the single invocation: -j CONNMARK --set-xmark 0x401/0xfffffbdf - To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html