On Thursday 2010-11-18 11:48, Dong-Yuan Shih wrote: >hi all > >a netfilter kernel module hoot at PREROUTING >and forward packet >--------------------------- >...... > >decide outgoing path > >...... >ip_forward(sk_buff) >return NF_STOLEN >-------------------------- > >iptables -t mangle -A FORWARD -s 192.168.1.0 -j MARK --set-mark 0xa > >traffic never match rule in FORWARD chain >any function can make traffic through FORWARD chain > >thanks for any advice 42. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html