Hello,
I think there's a bug in the behaviour of the multiport module - for
example, a line like
iptables -p tcp -A OUTPUT -m multiport ! --dport 25 -j DROP
causes the same behaviour as
iptables -p tcp -A OUTPUT -m multiport --dport 25 -j DROP
or
iptables -p tcp -A OUTPUT --dport 25 -j DROP
and NOT (as one would expect) that one caused by
iptables -p tcp -A OUTPUT ! --dport 25 -j DROP
Inverting the (set of) port(s) due to the "!" sign in the first line
above is just ignored
(no syntax error occures)!
Any comments?
Thanks,
Christoph