#iptables -vnL -t mangle Chain PREROUTING (policy ACCEPT 425K packets, 395M bytes) pkts bytes target prot opt in out source destination 0 0 MARK tcp -- vtun+ * 0.0.0.0/0 0.0.0.0/0 MARK xset 0x2/0xff 1705K 2048M QOS_MARK_ge00 all -- ge00 * 0.0.0.0/0 0.0.0.0/0 [goto] mark match 0x0/0xff 188K 86M fwmark all -- * * 0.0.0.0/0 0.0.0.0/0 Chain INPUT (policy ACCEPT 7359 packets, 840K bytes) pkts bytes target prot opt in out source destination Chain FORWARD (policy ACCEPT 417K packets, 394M bytes) pkts bytes target prot opt in out source destination 417K 394M mssfix all -- * * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy ACCEPT 6780 packets, 1182K bytes) pkts bytes target prot opt in out source destination 9872 640K DSCP udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport ports 123,53 DSCP set 0x24 Chain POSTROUTING (policy ACCEPT 424K packets, 395M bytes) pkts bytes target prot opt in out source destination 1114K 141M QOS_MARK_ge00 all -- * ge00 0.0.0.0/0 0.0.0.0/0 [goto] mark match 0x0/0xff Chain QOS_MARK_ge00 (2 references) pkts bytes target prot opt in out source destination 2819K 2189M MARK all -- * * 0.0.0.0/0 0.0.0.0/0 MARK xset 0x2/0xff 848K 47M MARK all -- * * 0.0.0.0/0 0.0.0.0/0 DSCP match 0x08 MARK xset 0x3/0xff 152 9187 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 DSCP match 0x30 MARK xset 0x1/0xff 16322 938K MARK all -- * * 0.0.0.0/0 0.0.0.0/0 DSCP match 0x2e MARK xset 0x1/0xff 93 7068 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 DSCP match 0x24 MARK xset 0x1/0xff 104K 5431K MARK all -- * * 0.0.0.0/0 0.0.0.0/0 tos match0x10/0x3f MARK xset 0x1/0xff Chain fwmark (1 references) pkts bytes target prot opt in out source destination Chain mssfix (1 references) pkts bytes target prot opt in out source destination 157 9524 TCPMSS tcp -- * ge00 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x02 /* wan (mtu_fix) */ TCPMSS clamp to PMTU