-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ming-Ching Tiew : > I still have more questions with ipset, I noticed that in the > portmap, there is no mentioned of protocol, whether should it be > tcp or udp. Taking the example from the url :- > > http://ipset.netfilter.org/features.html > > iptables -A FORWARD -m set --set servers dst,dst -j ACCEPT iptables > -A FORWARD -j DROP > > You notice that the ipmap 'server' binds to a portmap, but there is > no mentioned of protocol ( whether it should be tcp or udp ). > > Does it mean I have to specify the protocol in the iptables > command, Shoudn't there be a way the protocol be mentioned in the > binding somewhere ? Ip and the port can determine a package , why you need protocol ? -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFFMysu7tZp58UCwyMRAlnVAKDWKKw8I3KYLzSUzJpqttopyFX0MgCg1z8I bhvgoiUxyfrs/ht4HlXW/u0= =HoXR -----END PGP SIGNATURE-----