Hi, On Thursday 15 September 2005 14.09, Baake, Matthias wrote: > try to split up your input rules into some custom chains that the > packets have not a really long way to traverse your input chain thats > what i would do.. Or you could try using IPSet, maybe you can simplify your ruleset using the set match. http://ipset.netfilter.org -- Regards, Krisztian Kovacs