This morning as I was reviewing the changes occuring between 1.3.12 and 1.3.14, I noticed that I had neglected to document one new feature included in 1.3.14. In /etc/shorewall/tcrules, the MARK value may be optionally followed by ":" and either ''F'' or ''P'' to designate that the marking will occur in the FORWARD or PREROUTING chains respectively. If this additional specification is omitted, the chain used to mark packets will be determined by the setting of the MARK_IN_FORWARD_CHAIN option in shorewall.conf. -Tom -- Tom Eastep \ Shorewall - iptables made easy Shoreline, \ http://www.shorewall.net Washington USA \ teastep@shorewall.net