On Thursday 2009-03-12 16:13, Christoph Paasch wrote: >As NF_DROP = 0, no packets would ever have been dropped. Mh would not it be safer to actually give NF_DROP a real value so that -NF_DROP also makes sense? (Might need checking places where NF_DROP is used.) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html