Hi In which cases does the reroute-check in this picture take place? http://jengelh.hopto.org/images/nf-packet-flow.png I see the packets in raw.OUTPUT and mangle.OUTPUT. I do set a mark in mangle.OUTPUT (and I log it to be sure). Then I see the packet in filter.OUTPUT and mangle.POSTROUTING. Note: I don't see it in nat.OUTPUT or nat.POSTROUTING, but I think that's okay. But an "ip rule fwmark" does not work. (out-interface stays the same, even though the routing table refered by the ip rule only contains a default gateway on another interface.) So I think the reroute-check is not done. So: Does the kernel always reroute? Or does it have to be triggered? Regards, Steffen
Attachment:
smime.p7s
Description: S/MIME cryptographic signature