> Just for the archives: though it is seen so often - just google for > iptables scripts and you will find it - to use rules for protocol type > UDP with -m state makes no sense. UDP is, in opposition to TCP, a > stateless protocoll and this way does not know anything about NEW or > ESTABLISHED or what else. > You certainly will find it...100 times and rarely done the same way twice, without the give-and-take found here discussing which approach is better. In this case, the mailing list is a better option than google.