Just to add, with ipset having entry for 0.0.0.0/0,eth0 if I test ipset -T foo 192.168.100.100,eth0 its returns success. But in iptables rule it is not matching. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html