Hi Pablo, another useful feature of ipset is that the same set is usable in the filter, nat, and mangle tables. If I'm not mistaken, sets in nftables are right now scoped within a table, so I could not reuse them in that fashion. Am I mistaken? Or, is that another thing on the invisible roadmap? :) best regards Patrick -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html