H. Peter Anvin just mentioned something interesting to me, basically it's the fact that when your prefix addresses change on an interface in ipv6, this can invalidate your netfilter rules. So it would be nice if there were some way to match "the ipv6 prefix address on interface X", and through some kind of caching this could be optimized so it wouldn't really cost anything. Thoughts? -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html