This morning, I have added a TEST column to /etc/shorewall/routes to allow routing to be dependent on packet/connection marks. I have placed the TEST column _before_ the INTERFACE column which means that this change is not upwardly compatible. If you already have entries in /etc/shorewall/routes, you will need to change them when you install the latest version. Sorry for the inconvenience but these things sometimes happen with bleeding edge code. I believe that by combining packet/connection marking with entries in /etc/shorewall/routes, most scenarios involving multiple internet connections can now be handled. -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key