Thanks guys for pointing out, though I am still confused with the different between -t nat and -t mangle (on the bridge, and I am not doing NAT on my network what options should I use) .. I think am going to read the man page more carefully.. DET -----Original Message----- From: netfilter-admin@xxxxxxxxxxxxxxxxxxx [mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx] On Behalf Of Antony Stone Sent: Tuesday, May 04, 2004 6:34 PM To: netfilter@xxxxxxxxxxxxxxxxxxx Subject: Re: iptables: invalid arguement with kernel 2.6.5 On Tuesday 04 May 2004 12:00 pm, Det Buaklee wrote: > /sbin/iptables -A PREROUTING -t mangle -i eth0 -p tcp --dport 80 -j > REDIRECT --to-port 8080 > > or > > /sbin/iptables -t mangle -A PREROUTING -m physdev --physdev-in eth0 -p > tcp --dport 80 -j REDIRECT --to-port 8080 > > and iptables just return > > iptables: invalid argument REDIRECT should be done in the nat table, not the mangle table. Antony. -- Software development can be quick, high quality, or low cost. The customer gets to pick any two out of three. Please reply to the list; please don't CC me.