Looking through the archives, I see this was brought up previously, and the answer was 'no' - cite https://www.spinics.net/lists/netfilter-devel/msg49574.html What I *actually* want to do is whitelist SIP traffic (unencrypted) from various remote hosts, hopefully using a set of valid strings (eg, bytes 10 to 20 of the packet must be in the set X, which contains "AAAAAAAAAA", "BBBBBBBBBB" and "CCCCCCCCCC" for example) I was browsing through the RHEL 7.5 release notes, and noticed that they've pulled 0.8 in, so I was hopefully thinking that I could do this in nftables, but it appears it's still on the wishlist. Any news, or, anything I can help with? --Rob -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html