man iptables
man ip6tables
http://www.frozentux.net/documents/iptables-tutorial/
man nmap
我設定好了 iptables 條件,但使用 nmap 會有衝突出錯
sendto in send_ip_packet_sd: sendto(4, packet, 44, 0, 12.345.67.89, 16) => Operation not permitted
Offending packet: TCP 192.168.1.叉刹诧:47447 > 12.345.67.89:139 S ttl=55 id=63753 iplen=44 seq=3974890284 win=1024 <mss1460>
.....
必需在 iptables OUTPUT 鏈加
iptables -A OUTPUT -m state --state NEW,ESTABLISHED,REALATED,INVALID -j ACCEPT
INPUT 鏈加(這我原本就有)
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT