On Wednesday 2008-05-14 22:21, Jürgen Rochol wrote: > >Putting in a simple way, is the packet evaluated under a unique single >rule list or several rules lists -- one for each chain? Sieve principle. What has not matched falls through until it finally matches (and takes a terminating action). Much like, uh, filters. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html