Iptables-m extension
-m state
-- state {NEW,ESTATBLISHED,INVALID,RELATED} specifies which state to detect
Iptables-An INPUT-p tcp-m state-- state NEW,ESTABLISHED-j ACCEPT
Iptables-An OUTPUT-p tcp-m state-- state NEW,ESTABLISHED-j ACCEPT
-m multiport specifies multiple port numbers
-- sport
-- dport
-- ports
Iptables-An INPUT-p tcp-m multiport-- dport 22Magol 80pct 8080-j ACCEPT
Iptables-An OUTPUT-p tcp-m multiport-- sport 22Magol 80pct 8080-j ACCEPT
-m iprange specifies the IP segment
-- src-range ip-ip
-- dst-range ip-ip
Iptables-An INPUT-p tcp-m iprange-- src-range 100.0.0.0Universe 24-- dport 80-j ACCEPT
Iptables-An OUTPUT
-m connlimit connection qualification
-- comlimit-above # limit the number of Dalian connections
-m limit now has a connection rate, that is, limiting the number of matching packets
-- limit specified rate
-- limit-burst # Peak rate, maximum limit
-m string is qualified by string
-- algo bm | kmp specifies the algorithm bm or kmp
-- string "STRING" specifies the string itself