I have two very large address tables. One has 2500 lines and blocks all of china, the other has 900 and blocks all of korea.
When I use compile time, it works perfectly but takes a very long time to compile When I use runtime, the firewall basically blocks ALL incoming traffic.
I did an iptables-save with both the compile time and the runtime versions and I am attaching a diff of the two files so you can see the differences. If you like I can also send you the complete files but they are rather large because of over 3000 address blocks.
the firewall is running CentOS5.3 and iptables.