On Wednesday 18 February 2004 6:26 pm, capsx wrote: > ! > > I want as source to specify a chain > not -s 10.0.0.0/27 but something like -s LOCAL_NET_CHAIN You can't do that. -s takes an address or network range. -i takes an interface name. You cannot specify anything else as the 'source' of a packet. Tell us why you want to do this and we might be able to suggest an alternative (MARKing packets comes to mind, for example). Regards, Antony. -- What is this talk of "software release"? Our software evolves and matures until it is capable of escape, leaving a bloody trail of designers and quality assurance people in its wake. Please reply to the list; please don't CC me.