Hi, Could you give me the best way to verify if my configuration is "policy match" ready? My OS is Debian: Kernel is 2.6.16 (unstable arg...) own compiled iptables 1.3.5 --> my shorewall still display "Your kernel and/or iptables does not support policy match: ipsec" :-( thanks a lot! Matthieu ps: sorry for my english