Hi Jozsef, Many thanks for ipset. Quick question please: I'm implementing a captive portal and I have an ipset (CP) containing bitmap:ip,mac. How should I best implement rules to: - Drop packets from same IP, different MAC I might be missing the obvious, but how do I query to match on IP, then drop IP with a mismatching MAC (in the bitmap ipset)? Can this be done without a second ipset tracking only IP? Thanks for any tips? Ed W -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html