4 ms·
Iptables applies to all processed packets. One of the common gotchas though is that if you add a rule to allow "Established" connections, and then try to add a
by click170 11y ago
Iptables applies to all processed packets.
One of the common gotchas though is that if you add a rule to allow "Established" connections, and then try to add a new rule after that which says "block IP X", that will not sever existing connections.
To block existing connections you can remove that entry from the connection tracking table, or you can insert your "block IP X" rule above your "allow Established connections rule".