>If you are refering to the OUTPUT chain of the Dom0 itself, 
surely
>you wouldn't use physdev at all? Wouldn't you just use "iptables 
-A
>OUTPUT -o ethx ...."?
Dunno about iptables specifics - I only 
use Shorewall and I know it's
a limitation. But isn't "-o ethx" a device 
match ?
If there was a way around the limitation, I'm sure Tom Eastep 
would
have figured it out.
 
-----------------------------------------------------------------------------------------------------
Hi Simon,
 
Yes, "-o ethx" is indeed a device match, but it works differently 
to physdev, which really only works well on fordwarded traffic (Although I think 
it is supposed to work on all bridged traffic)
 
Can you please post a link to information about this? I can't find 
anything on Google about this.
 
Thanks