well... it doesn't. I tested it once more with sarge/stable and 2.4 kernel.
Funny thing: when the "ip rule fwmark" is added then the next rule - with lower preference - is checked, too (it can be main or "ip rule from" or anything). If the routes set by these 2 rules are the same then packet is accepted. If not then it's dropped. Thanks for your intrest... but I will not use Debian :/ -- Tomek -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]