Hello list, to put it straight: I have found that kernel threads (read: nfsd) do not match --uid-owner 0, i.e. have the same issue as e.g. ICMP messages (as said in the OWNER part of the manpage). Is there any way to match these sort of packets without using port ranges? 2049 is not always true.. Jan Engelhardt -- | Alphagate Systems, http://alphagate.hopto.org/