Le mer 11/02/2004 à 22:53, Richard Bown a écrit : > I suspect from the results I've seen running 2.6.2 with iptables-1.2.9 > that the handling of DNAT & SNAT is very different. Afaik, from a user point of vue, there's no difference between 2.4 and 2.6. I'm using a 2.6.1 kernel on which all the scripts I've written for 2.4 kernels are working just the way they did before, for filtering, mangling and nating... What kind of results makes you believe there are major differences on NAT handling ? One big difference is bridge interfaces handling, as physical interfaces cannot get matched using -i/-o switches anymore (br0 is seen through them) so you have to use physdev match. -- http://www.netexit.com/~sid/ PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE >> Hi! I'm your friendly neighbourhood signature virus. >> Copy me to your signature file and help me spread!