12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using IPTables Match Extensions 483conntrackMatch packet according to its connection state.--ctstate Replace with a comma-separated list of states. Possible states:. INVALID: Packet is not associated with a known connection.. ESTABLISHED: Packet is associated with an established connection, meaning ithas sent packets in both directions.. NEW: Packet is associated with a new connection that has not sent packets inany direction or has started a new connection.. RELATED: Packet has started a new connection associated with an existingconnection.. SNAT: Original source address for the packet is different from the replydestination.. DNAT: Original destination address for the packet is different from the replysource.24--ctproto Match a given protocol by its name or number.--ctorigsrc [!] /Match packets with a specified original source address. Address mask is optional.--ctorigdst [!] /Match packets with a specific original destination address. Address mask isoptional.--ctreplsrc [!] /Match packets with a provided reply source address. Address mask is optional.--ctrepldst [!] /Match packets according to reply destination address. Address mask is optional.--ctstatus Match packets according to internal conntrack state.--ctexpire :Packets match if its remaining lifetime is within a range, provided in seconds.The maximum time is optional.dccpMatch based on DCCP.--source-port,--sport [!] :Match according to minimum source port number or a range.--destination-port,--dport [!] :Match according to minimum destination port number or a range.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!