Simply wouldn't work. Iptables used is 1.4.12 and kernel is 2.6.36. Older 2.6 kernel (2.6.12) +iptable combos seems to work. Also, "set-return" command for CONNMARK seems to be gone which is extensively used by TOMATO QOS. WHat is it replaced with? Appreciate the help!