yes,..this is the problem ... 2011/4/22 Jan Engelhardt <jengelh@xxxxxxxxxx>: > On Friday 2011-04-22 12:05, Lu Brian wrote: > >>if u nslookup www.facebook.com,you can get different resolved ip >>almost every time. > > But you get only one, and that is what counts. And from that you cannot > make an assessment how many more addresses they potentially have. > >>Many webs use this kind of wrr dns reply method. It means I need to >>find out all of the resolved ip manually and then add rules for all of >>the resolved ips... > -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html