On Friday 2012-06-15 14:51, Hans Schillstrom wrote: > >As I wrote in my first mail IPv6 is a different story, you don't >have any options there since you are not allowed to "re-frag" the >packet Here's another point I remember why we forced IP_DF: we want to keep the packet as-is. The receiver of the cloned packet (often a logger) has no way of autonomously knowing whether the packet was already fragmented originally as it came into the cloner, or whether fragmentation is a doing of the cloner. Maybe should just add that as a comment for completeness of the history. :) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html