On 15.11.2010 02:30, Jan Engelhardt wrote: > netfilter: xt_LOG: do print MAC header on FORWARD > > I am observing consistent behavior even with bridges, so let's unlock > this. xt_mac is already usable in FORWARD, too. Section 9 of > http://ebtables.sourceforge.net/br_fw_ia/br_fw_ia.html#section9 says > the MAC source address is changed, but my observation does not match > that claim -- the MAC header is retained. I've checked the code and I think you're right, even IPsec tunnels make sure to preserve the original MAC header. Applied, thanks. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html