On Friday 2011-04-22 12:05, Lu Brian wrote: >if u nslookup www.facebook.com,you can get different resolved ip >almost every time. But you get only one, and that is what counts. And from that you cannot make an assessment how many more addresses they potentially have. >Many webs use this kind of wrr dns reply method. It means I need to >find out all of the resolved ip manually and then add rules for all of >the resolved ips... -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html