Hi Richard, Richard wrote: >I drop it and also implemented other suggestions. Here is the latest. > > I've converted your target to a match because that way we can use ctexpire together with NAT actions in the same rule. This was inspired by reading ipt_limit. I've done some minor cleanups and a checking to make sure that this match is never used in the raw table. Would like to send to the list a version for patch-o-matic-ng? Then we could push it to the SVN repository. -- Pablo