<0> I think it will only operate on the IP part <1> if i could regex the headers..:P
<0> you could write a simple libipq application to do that <0> perl has a library :) <1> libipq? <0> the QUEUE target, sends packets to userspace for filtering
<2> But it might be just as easy to hack the libipt_mac source :) <0> well, that would at least require compiling the kernel module, and probably also recompile the iptables -m mac interface too