a question i just saw posted on another list -- when you select an interface in a rule, like "eth0", does that include all of its aliases like eth0:0, eth0:1, and so on? i would have initially thought yes, but if each of these aliases can have a different IP address associated with it, what happens when you add a destination IP address selector such as "-d 10.1.2.3", which is associated to only one of those aliases? or am i making any sense? rday