Hi I marked few types of traffic: $IPTABLES -t mangle -A PREROUTING -p tcp -j CONNMARK --restore-mark $IPTABLES -t mangle -A PREROUTING -p tcp -m mark ! --mark 0 -j ACCEPT $IPTABLES -t mangle -A PREROUTING -p tcp -m ipp2p --ipp2p -j MARK --set-mark $P2P $IPTABLES -t mangle -A PREROUTING -p tcp --dport 21 -j MARK --set-mark $FTP $IPTABLES -t mangle -A PREROUTING -p tcp --dport 80 -j MARK --set-mark $WWW $IPTABLES -t mangle -A PREROUTING -p tcp -j CONNMARK --save-mark With rules below I can count traffic of this types: $IPTABLES -t mangle -A POSTROUTING -m mark --mark $P2P -j ACCEPT $IPTABLES -t mangle -A POSTROUTING -m mark --mark $FTP -j ACCEPT $IPTABLES -t mangle -A POSTROUTING -m mark --mark $WWW -j ACCEPT But I want count all other traffic, not marked with marks $P2P, $FTP, $WWW withe speparated rule. How can I do that? -- Pozdrawiam Marcin mailto:slacklist@xxxxx