From mboxrd@z Thu Jan 1 00:00:00 1970 From: Franck JONCOURT Subject: Re: CONNMARK and ip rule fwmark Date: Sun, 30 Mar 2008 17:08:15 +0200 Message-ID: References: Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: Sender: netfilter-owner@vger.kernel.org List-ID: Content-Type: text/plain; charset="us-ascii" To: netfilter@vger.kernel.org [...] >> What about using the nat table to add your mark on a whole connection >> instead of using the mangle table ? > > Using the nat table to 'simulate' -m conntrack --ctstate NEW, that's > just a gross hack IMO. Oh and as soon as you start using IPv6, > there is no nat, so do not even think of doing it :p Ok, thanks for your point of view I did not think about that. I am going to change some stuff :)! --- Franck Joncourt http://www.debian.org/ - http://smhteam.info/wiki/