> I don't quite understand why (although I agree that it's remotely possible), It is especially possible when you have some kind of daemon that's automatically inserting netfilter rules :) > so how about using -D instead of -A (or -I) with exactly the same parameters > as you specified when adding the rule? Unfortunatelly that doesn't work with a -m quota rule. Since the delete will the exact state of the quota (that you can't atomically get) :( -- damjan | ÐÐÐÑÐÐ This is my jabber ID --> damjan@xxxxxxxxxxxx <-- not my mail address!!!