Thanks for all your help, I think with your advice I can progress with this problem now. I've added the information you provided to the stackoverflow question in case anybody else meets with a similar problem in future: http://stackoverflow.com/questions/24397358/iptables-matching-packets-leaving-a-bridged-interface -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html