iptables -P INPUT DROP iptables -P OUTPUT DROP iptables -P FORWARD DROP |
iptables --append (CHAIN) (selection-criteria) --jump (TARGET) |
iptables -A (CHAIN) (selection-criteria) -j (TARGET) |
iptables -A INPUT -p tcp --dport 25 -j ACCEPT iptables -A OUTPUT -p tcp --sport 25 -j ACCEPT |
iptables -A INPUT -s 192.168.5.0/24 -j ACCEPT iptables -A OUTPUT -d 192.168.5.0/24 -j ACCEPT |
-m state
--state: INVALID
NEW
ESTABLISHED
RELATED
|
iptables -A INPUT -m state -p tcp --dport 80 -s 192.168.5.0/24 --state NEW,ESTABLISHED,RELATED -j ACCEPT iptables -A OUTPUT -m state -p tcp --sport 80 -d 192.168.5.0/24 --state ESTABLISHED,RELATED -j ACCEPT |