On 04.11.2010 03:12, H. Peter Anvin wrote: > On 11/03/2010 06:52 PM, Jan Engelhardt wrote: >> >> I take it you mean a setup where addresses are automatically assigned >> (DHCPv6, PPP). >> > > DHCPv6, PPP, RA, anything. Keep in mind that "expect prefix changes" is > a deliberate part of the IPv6 systems design. Do we have a way to identify the prefix(es) in question for the ruleset? IOW, do the userspace daemons replace the existing prefix or adds a new one and removes the old one? The kernel itself seems to make sure the autoconfigured local address is always the first one on the interface. If userspace does the same this should be pretty easy. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html