On Tue, Mar 22, 2005 at 05:06:39PM +0100, Toby wrote: > Dear netfilter users, > > I've found it handy to put filtering rules in the nat table, <--snip--> do *NOT* filter in the nat table. only --state NEW packets ever traverse the nat table. if you want to filter packets pre-filter table, do it in mangle. -j