OMG THANK GOD I JUST FOUND IT!!!! it was hidden and off by default!! The tcp_fwmark_accept was off by default! sudo sysctl -w net.ipv4.tcp_fwmark_accept=0 -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html