>Hi, is me once again. Hi, >I tried this for a test box and the download speed worked correctly: >... I see you already nailed it ;-). >So, are these ruleset more convenient than the one I currently have? Simple u32 won't scale any better then ipt marking + tc fw filter. Real performance gain is in use of hashing filters. Best regards, Marek Kierdelewicz -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html