> I have two thousand hosts and two thousand forward rules :( With so many hosts/rules you should be able to match subnets instead of each host separately, reducing the number of rules greatly which in turn improves Netfilter performance. Or do you have a special reason to do this ? Gr, Rob