Balazs Scheidler <bazsi@xxxxxxxxxx> wrote: > the only issue I see with this solution is that late packets will not be delivered to the proper socket, and will possibly be going to the fwd chain, which might be unexpected. Why? They'll get the proper nfmark, so they will be routed to the local machine. The tcp stack should find the tw socket via normal sk lookup. Or am i missing something? -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html