Don't anyone have any clues for the problem I sent to the list on sunday? I find it really strange that decrypted packets coming from ipsec tunnel with destination address xx.xx.xx.42 are sent through interface ext1 even though ip -s route get xx.xx.xx.42 says that packet should go through interface ext0b. Ipsec tunnel itself is going through inteface ext1 but shouldn't packets get routed after they come from tunnel? I even tried to look at kernel code to figure out why this happens but I don't know enough about kernel and my c skills are a bit lacking, so I couldn't find the cause. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html