On Sun, Jun 01, 2008 at 09:19:40AM +0000, 李伟华 wrote: > but when i use iptables add mark to out-traffic and use ip rule with fwmark like this: > iptables -t mangle -A PREROUTING -s SOME_IP -j MARK --set-mark 11 > ip rule add fwmark 11 table ISP2 > > the SOME_IP computers can't access internet , what's wrong ? Does anyone have hints ?QUW1 Maybe it's caused by rp_filter according to the following mail, if that information is still valid: http://lists.netfilter.org/pipermail/netfilter/2000-November/006089.html -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html