> >>>> Why doesn't iptables works with vlans? > >>>> iptables -t mangle -A FORWARD -i eth0 -o eth1.11 -j MARK --set-mark 4 It does for us, though I don't think we've tried the mangle table. iptables-1.2.7a-2 with kernel-2.4.20-31.9_v1_dice_1, and also iptables-1.2.11-3.1.FC3 with kernel-2.6.12-1.1372_FC3. I think the only slightly non-default thing we've done is to have set VLAN_NAME_TYPE=VLAN_PLUS_VID_NO_PAD. -- Dr George D M Ross, School of Informatics, University of Edinburgh Kings Buildings, Mayfield Road, Edinburgh, Scotland, EH9 3JZ Mail: gdmr@xxxxxxxxxxxx Voice: +44 131 650 5147 Fax: +44 131 667 7209 PGP: 1024D/AD758CC5 B91E D430 1E0D 5883 EF6A 426C B676 5C2B AD75 8CC5 -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 239 bytes Desc: not available Url : http://www.candelatech.com/pipermail/vlan/attachments/20050927/725a1ca2/attachment-0001.bin