On Thu, 2003-03-13 at 14:40, alexb@xxxxxxxxxxx wrote: > But how do I distinguish RELATED connection from ftp and H323 ? > If I only whant to limit bandwidht for ftp and not for H323, how could I tell > iptable to mark only the RELATED packets from ftp connections ? You better use the connmark target to suit your need. You can find a little doc about it on : http://home.regit.org/connmark.html The process is the following : you mark initial packet connmark restore a mark related to the connection. BR -- Eric Leblond <eleblond@xxxxxxxxxxxx> Init-Sys