QUOTE:原帖由 sxh77 于 2006-4-7 16:19 发表
iptables -A FORWARD -p tcp --dport 21 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
条件越复杂,匹配内容越少,匹配范围越窄
iptables -A FORWARD -p tcp --dport -j ACCEPT
iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT