Hi, I would like to bring up the question, if there is a way to associate a nfmark with a socket. It would be very helpful as it saves the matching against iptables rules which would have to than match the packet and associate the nfmark. The same question was already posted here: http://lists.netfilter.org/pipermail/netfilter/2002-October/039074.html Thanks for your responses Tomas