hi afaik it is possible, but the hostname will be resolved if the rule is executed. this means if there is a dns update, the resolved ip may not match the hostname you want to filter. so i would say better be careful greets Matthias > -----Original Message----- > From: netfilter-bounces@xxxxxxxxxxxxxxxxxxx > [mailto:netfilter-bounces@xxxxxxxxxxxxxxxxxxx]On Behalf Of rockey dada > Sent: Tuesday, August 30, 2005 2:58 PM > To: netfilter@xxxxxxxxxxxxxxxxxxx > Subject: FQDN filtering > > > Is there any way one can use IPTABLES to filter traffic based > on "Fully > Qualified Domain Names". > > Rgds > > __________________________________________________ > Do You Yahoo!? > Tired of spam? Yahoo! Mail has the best spam protection around > http://mail.yahoo.com > >