Hi, I want to get conntrack update events for all connections that go through FORWARD, but not through INPUT or OUTPUT. I tried to set a connmark bit and check for the mark. But I saw no way to filter for a given mark value using a kernel filter. Did I miss something? I already filter in userspace, but I want to avoid this if possible. Regards, -- Tino Keitel Software Engineer Innominate Security Technologies AG /protecting industrial networks/ Tel: +49.30.921028-206 Fax: +49.30.921028-020 Rudower Chaussee 13 12489 Berlin / Germany http://www.innominate.com/ Register Court: AG Charlottenburg, HRB 81603 Management Board: Dirk Seewald, Chairman of the Supervisory Board: Volker Bibelhausen -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html