Hi all, I read the docu and I read the FAQ, I still don''t know where and how I should include the rules the mark packets for SNORT-inline. They need to be marked in the "in"-queue of the external interface *before* any firewall rules are applied. Any hints welcome. Philipp