On Sat, Oct 31, 2015 at 01:56:39PM +0100, Jakub Sztandera wrote: > Hello, > > we have recently transitioned from iptables to nftables. Our network architecture isn't simple > but it can be simplified for the sake of this message. > We also use a lot of LXC (cgroups) and we suspect that it might play a role in this case. Please, indicate kernel and nftables version. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html