Hello everybody, One more question. :-) AFAICS, the majority of iptables scripts available in the Internet use PREROUTING chain to mangle TOS values. Are there any benefits of using PREROUTING but not FORWARD or, say, POSTROUTING? (It seems that in certain situations it is easier to write a rule for FORWARD chain rather than for PREROUTING one.) Thanks! Mikhail