netfilter-devel: I use linux-2.6.18, and i have a ipsec vpn client and server, there are two swicthes using vlan trunk of 802.1Q between of the vpn client and server. I placed a linux bridge in the middle of two swicthes. I ping vpn server using normal package from vpn client to vpn server is ok, but i ping vpn server using big package(3000 len) from vpn client is error when netfilter is running. If i add "echo 0 > /proc/sys/net/bridge/bridge-nf-filter-vlan-tagged", the big package is passed. So i don't known whether there is error when netfilter deals with the vlan-ipsec big packet. Thanks a lot! ligangfeng E-mail:flg2932946@xxxxxxx ==================================================== 2010-04-26 ?韬{.n?????%??檩??w?{.n???租??庄z_??n?■???h?璀?{?夸z罐?+€?zf"?????i?????_璁?:+v??撸?