On 20 December 2016 at 12:24, Llorente Santos Jesus <jesus.llorente.santos@xxxxxxxx> wrote: > Hi, > > I have been playing quite a bit with iptables lately. Ever since the ipset was updated to support hash:ip,mark sets, there has been the potential to apply efficient matching on packet marks. > Does it make any sense to you to develop a new extension that following U32 and MARK syntax would allow us to read a 32bit value and load it onto the packet mark ? It guess what makes sense is to switch to nftables :-) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html