Hello John, Thank you for your answer - that was an option I had not thought of, so I'm going to investigate.. One other issue I just realised with this setup has to do with ARP. Is it possible to ensure that control-connection related ARP requests only get onto the control network interface and data-connection related requests only get sent on the data network interface? Especially with the two networks having an overlapping IP range I need to ensure that the request goes out on the correct network interface. Best regards, Edwin On Mon, June 21, 2010 14:45, John Lister wrote: > You might try looking at connection/packet marking. > > John > -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html