Hello again, I changed the source from a Address Range to a Network. Now I get this code:
$IPTABLES -N CHAIN $IPTABLES -A INPUT -i inet -s ! XX.X.X.X/8 -d YYY.YY.YYY.YY -j CHAIN This, of course, is correct. So it seems there is a bug in negated source Address Ranges. As destination they work fine. Daniel
signature.asc
Description: This is a digitally signed message part.

