Thank you for your hint, but the command-line you told doesn't work. The system keeps complaining (unknowg arg --dport). I also tried out the long version --destination-port with the same result. I looked at the manpage and found that iptables should know this argument, so there seems to be a syntax error. Anyone has an idea what is wrong and how the correct syntax is ?
The syntax is correct. Just move the -j option more to the beginning of
the command line. iptables parses the command line and dlopen()s shared
libraries depending on the options on the command line. If the (filtering)
target is too late, it won't accept the command and bails out. Known bug.
Thanks,
Roman.
--
- -
| Roman Drahtmüller