On Fri, Sep 30, 2005 at 01:34:01PM +0200, Sascha Reissner wrote: > eth1.11 is the same physical device as eth1. Doesn't matter here. > use eth1 in your rule and you are fine. Bad advice. eth1 is most probably a completely different IP network. > netfiler does IMHO not support filtering by logical interface. It does. I do, however, not know why the original poster's commandline is not accepted as it seems to be OK on first sight. Greetings Marc -- ----------------------------------------------------------------------------- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things." Winona Ryder | Fon: *49 621 72739834 Nordisch by Nature | How to make an American Quilt | Fax: *49 621 72739835