> >>So, maybe can we forbid iplist in vm rules ? (now we have ipset for this) > > Note, I thinked that it was breaking the digest (always updating the chain), > but it's not the case. > So we can keep it. Also OK for me ;-)