Hi, I hve explored the manual of SETtarget: SET target options: --add-set name flags [--exist] [--timeout n] --del-set name flags add/del src/dst IP/port from/to named sets, where flags are the comma separated list of 'src' and 'dst' specifications. I can not find solution for add a subnet mask to a hash:net with the target. Thanks for reading. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html