[root@localhost proftpd]# iptables --list
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp multiport dports ftp,ssh,10000
DROP icmp -- anywhere stereoz.***
ACCEPT all -- 10.254.0.1 anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
DROP all -- anywhere anywhere
ACCEPT all -- anywhere stereoz.*** state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpts:49152:65535
Chain FORWARD (policy DROP)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
и ни одна тварь не пролезет