Rules are executed "top down". So packets logged in an early rule and then rejected in a later rule get both logged and rejected. And I did somewhat misread the list. It looks like you want to both log and reject the 0:1023 material so you could -j REJECT -j LOG in a single rule, I believe. Please excuse my error. {^_^} ----- Original Message ----- From: "Tom Ball" <Tom.Ball@xxxxxxx> To: <shrike-list@xxxxxxxxxx> Sent: Monday, 2003 August, 11 15:52 Subject: Re: iptables: ignoring multicast packets > My LOG rules were first so the packets to be rejected were logged > first. Is the man page's LOG section wrong? That's where I got the > "duplicate rule and change REJECT to LOG" hack. -- Shrike-list mailing list Shrike-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/shrike-list