Hi, Protocols like HTTP are segmented, so I must rebuild the whole incoming packet prior to modify it. But with libnetfilter_queue, you receive one packet at time, and you just either ACCEPT or do other actions. Do you think there's a way to let libnetfiter_queue buffer the packet before sending to userland program? So that in the callback I will see the whole packet. Any ideas? Or other alternatives is welcomed! -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html