hi, will this rule : iptables -A ns_ul -s 10.0.0.99 -p tcp -m tcp --dport 80:100 -j MARK --set-mark 0x5 actually mark port range from 80 to 100 or only the 80 and 100 port ? (or maybe it means something else ? :) ) regards -- Wojciech Ziniewicz Unix SEX :{look;gawk;find;sed;talk;grep;touch;finger;find;fl ex;unzip;head;tail; mount;workbone;fsck;yes;gasp;fsck;more;yes;yes;eje ct;umount;makeclean; zip;split;done;exit:xargs!!;)}