It is possible (DROP exists in all tables), but should not be done.
I know that drop is only in INPUT, FORWARD and OUTPUT chain...
Can't you MARK packets in earlier chains (PREROUTING or FORWARD) and use the mark in POSTROUTING ?
perhaps it is the only solution but I would to recognize packets in POSTROUTING to send them in a IMQ virtual interface.
Fabio -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html