libxt_sctp.man 1.0 KB

12345678910111213141516171819202122232425262728
  1. .TP
  2. [\fB!\fP] \fB\-\-source\-port\fP,\fB\-\-sport\fP \fIport\fP[\fB:\fP\fIport\fP]
  3. .TP
  4. [\fB!\fP] \fB\-\-destination\-port\fP,\fB\-\-dport\fP \fIport\fP[\fB:\fP\fIport\fP]
  5. .TP
  6. [\fB!\fP] \fB\-\-chunk\-types\fP {\fBall\fP|\fBany\fP|\fBonly\fP} \fIchunktype\fP[\fB:\fP\fIflags\fP] [...]
  7. The flag letter in upper case indicates that the flag is to match if set,
  8. in the lower case indicates to match if unset.
  9. Chunk types: DATA INIT INIT_ACK SACK HEARTBEAT HEARTBEAT_ACK ABORT SHUTDOWN SHUTDOWN_ACK ERROR COOKIE_ECHO COOKIE_ACK ECN_ECNE ECN_CWR SHUTDOWN_COMPLETE ASCONF ASCONF_ACK FORWARD_TSN
  10. chunk type available flags
  11. .br
  12. DATA I U B E i u b e
  13. .br
  14. ABORT T t
  15. .br
  16. SHUTDOWN_COMPLETE T t
  17. (lowercase means flag should be "off", uppercase means "on")
  18. .P
  19. Examples:
  20. iptables \-A INPUT \-p sctp \-\-dport 80 \-j DROP
  21. iptables \-A INPUT \-p sctp \-\-chunk\-types any DATA,INIT \-j DROP
  22. iptables \-A INPUT \-p sctp \-\-chunk\-types any DATA:Be \-j ACCEPT