1. Does network traffic pass through the PREROUTING chain even for packets that are in the same subnet? 2. And a related question I asked in another thread. Reading through the "specific port openvpn" thread (http://www.linksysinfo.org/index.php?threads/route-only-specific-ports-through-vpn-openvpn.37240/) I noticed that multiple PREROUTING rules are being used. I thought iptables worked by the first rule that the packet matches gets selected. It seems that 'iptables -t mangle -A PREROUTING -i br0 -j MARK --set-mark 1' should match all traffic on the LAN and not go to the other rules. Does the PREROUTING chain not work that way? If not, how does it work?