I have tried using what I mentioned and I get error iptables -A FORWARD -m set --match-set foo src,mark -j ACEEPT iptables v1.4.21: You must spefify (the comma separated list of) 'src' or 'dst'. Try `iptables -h' or 'iptables --help' for more information. On Wed, Aug 26, 2015 at 2:39 PM, Akshat Kakkar <akshat.1984@xxxxxxxxx> wrote: > how to use hash:ip,mark in iptables ? > > I can create ipset, but how to match it in iptables? > > something like -m SET --match-set src,mark > > or something else altogether? -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html