On Fri, Apr 24, 2009 at 23:39:44 +1000, Brian Austin - Standard Universal wrote: > that should be 2 separate lines.. stupid email > > iptables -A INPUT -m mark --mark 1 > > iptables -A INPUT -m connmark --mark 2 I want to match packets with both a specific nfmark _and_ a specific connmark, so I need both matches in one rule. Regards, -- Tino Keitel Software Engineer Innominate Security Technologies AG /protecting industrial networks/ Tel: +49.30.921028-206 Fax: +49.30.921028-020 Rudower Chaussee 13 12489 Berlin / Germany http://www.innominate.com/ ---------------------------------------------------------------- Visit us at the Hannover Messe in Germany 20 - 24 April 2009, Hall 9, Stand F54 ---------------------------------------------------------------- Register Court: AG Charlottenburg, HRB 81603 Management Board: Dirk Seewald, Chairman of the Supervisory Board: Volker Bibelhausen INNOMINATE HAS MOVED. PLEASE NOTE THAT OUR BUSINESS CONTACT DATA HAS CHANGED. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html