> --socket-exists > I just want to check is there a local socket associated with the packet or not. Apologies; I have misunderstood what this flag does. You could try: `iptables -A FORWARD mark -j MARK --set-mark $FWD_TAG` `iptables -A OUTPUT -m connmark --mark ! $FWD_TAG -j LOG --log-prefix OWN_SK` Regards, sunny