Thanks for all the responses about the internals of NFTables The best starter document was this: https://workshop.netfilter.org/2016/wiki/images/7/78/Nft-tutorial.pdf Now I just need to figure out how to interpet the "payload load 4b @ network_header + 12" nomenclature to really get a handle on things. Any more documents or videos to understand the internals? (Instead of hours spent looking at source code!) Thanks, md -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html