Chris Hall <netfilter@xxxxxxx> wrote: > For input such as "-s 10.0.0.2/24", the 10.0.0.2 simply isn't a valid > network address for a /24 network. > > I agree: the parser should detect invalid input and reject it. I can see no > good reason for being sloppy here. It breaks current behaviour; we cannot change this 20 years later. Its as simple as that.