On Wed, Dec 13, 2023, at 10:48, Eric wrote: > On Tuesday, December 12th, 2023 at 22:56, ye4 yu3 <ye4yu3@xxxxxxxxxxx> wrote: >> As you said, I used tcpdump to check the status of the ip packets,The rule to set the port cannot be successfully executed, And i see the ip packet appears to be damaged in the tcpdump (they no longer have source and destination ports). > > That sounds like a bug (or by design?), maybe netdev tables don't know > about L4 ports? They do, I have rules successfully matching on L4 ports (but not modifying packets).