| 
 
 
"Lorn Kay" <lorn_kay@xxxxxxxxxxx> writes:
> Remember that once a packet matches a rule in a chain it is kicked out
> of the chain--it doesn't matter if it is an ACCEPT or REJECT
> rule(packets may never get to your FWMARK rules, for example, if they
> do not come before your ACCEPT and REJECT tests).
Huh?  FWMARK rules?  I've never seen those.  Last I looked a fwmark is
added with a -m flag on an ACCEPT rule -- at least it certainly works
that way on my LVS routers.  (Ok, you could probably mark a REJECT or
DENY rule, but it would be pretty pointless.)
Brian.
 
 |