On Wednesday 2008-04-09 21:17, Gilad Benjamini wrote: >True, but I am looking for a more optimized solution I assume ipset's iptree is smart enough to do short-circuiting if you have /24, /16 or /8 networks. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html