Hi all, I’d like to use this extension but I have my doubts on just how often it’s useful. It would be nice if there were a way to determine this concretely: perhaps it could be reimplemented as a matching filter, and only match on packets that had been changed. I suspect that most hosts do the right thing, and that most networks correctly pass ICMP Unreachable - Fragmentation Needed, etc. but being able to log packets where this isn’t the case and clamping turns out to be necessary would be a lot more useful. Anyone have any insight into this? Thanks, -Philip -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html