I've wasted most of this weekend trying to get per-user rules working correctly with fwbuilder/iptables/iproute2. For the purposes of this description, let's say: The firewall has two interfaces: eth1 ...