- * Core Netfilter Configuration
- *
- Netfilter NFQUEUE over NFNETLINK interface (NETFILTER_NETLINK_QUEUE) [N/m/y/?] (NEW) y
- Netfilter LOG over NFNETLINK interface (NETFILTER_NETLINK_LOG) [N/m/y/?] n
- Netfilter connection tracking support (NF_CONNTRACK) [Y/n/m/?] y
- Connection tracking flow accounting (NF_CT_ACCT) [N/y/?] (NEW) y
- Connection mark tracking support (NF_CONNTRACK_MARK) [N/y/?] (NEW) y
- Connection tracking events (NF_CONNTRACK_EVENTS) [N/y/?] (NEW) y
- DCCP protocol connection tracking support (EXPERIMENTAL) (NF_CT_PROTO_DCCP) [N/m/y/?] (NEW) y
- SCTP protocol connection tracking support (EXPERIMENTAL) (NF_CT_PROTO_SCTP) [N/m/y/?] (NEW) y
- UDP-Lite protocol connection tracking support (NF_CT_PROTO_UDPLITE) [N/m/y/?] (NEW) y
- Amanda backup protocol support (NF_CONNTRACK_AMANDA) [N/m/y/?] (NEW) y
- FTP protocol support (NF_CONNTRACK_FTP) [Y/n/m/?] y
- H.323 protocol support (NF_CONNTRACK_H323) [Y/n/m/?] y
- IRC protocol support (NF_CONNTRACK_IRC) [N/m/y/?] n
- NetBIOS name service protocol support (NF_CONNTRACK_NETBIOS_NS) [N/m/y/?] (NEW) y
- PPtP protocol support (NF_CONNTRACK_PPTP) [N/m/y/?] (NEW) y
- SANE protocol support (EXPERIMENTAL) (NF_CONNTRACK_SANE) [N/m/y/?] (NEW) y
- SIP protocol support (NF_CONNTRACK_SIP) [Y/n/m/?] y
- TFTP protocol support (NF_CONNTRACK_TFTP) [Y/n/m/?] y
- Connection tracking netlink interface (NF_CT_NETLINK) [N/m/y/?] n
- Transparent proxying support (EXPERIMENTAL) (NETFILTER_TPROXY) [N/m/y/?] (NEW) y
- Netfilter Xtables support (required for ip_tables) (NETFILTER_XTABLES) [Y/?] y
- "CLASSIFY" target support (NETFILTER_XT_TARGET_CLASSIFY) [N/m/y/?] (NEW) y
- "CONNMARK" target support (NETFILTER_XT_TARGET_CONNMARK) [N/m/y/?] (NEW) y
- "DSCP" and "TOS" target support (NETFILTER_XT_TARGET_DSCP) [N/m/y/?] (NEW) y
- "MARK" target support (NETFILTER_XT_TARGET_MARK) [N/m/y/?] n
- "NFLOG" target support (NETFILTER_XT_TARGET_NFLOG) [N/m/y/?] n
- "NFQUEUE" target Support (NETFILTER_XT_TARGET_NFQUEUE) [N/m/y/?] (NEW) y
- "RATEEST" target support (NETFILTER_XT_TARGET_RATEEST) [N/m/y/?] (NEW) y
- "TPROXY" target support (EXPERIMENTAL) (NETFILTER_XT_TARGET_TPROXY) [N/m/y/?] (NEW) y
- "TCPMSS" target support (NETFILTER_XT_TARGET_TCPMSS) [N/m/y/?] n
- "TCPOPTSTRIP" target support (EXPERIMENTAL) (NETFILTER_XT_TARGET_TCPOPTSTRIP) [N/m/y/?] (NEW) y
- "comment" match support (NETFILTER_XT_MATCH_COMMENT) [N/m/y/?] (NEW) y
- "connbytes" per-connection counter match support (NETFILTER_XT_MATCH_CONNBYTES) [N/m/y/?] (NEW) y
- "connlimit" match support" (NETFILTER_XT_MATCH_CONNLIMIT) [N/m/y/?] (NEW) y
- "connmark" connection mark match support (NETFILTER_XT_MATCH_CONNMARK) [N/m/y/?] (NEW) y
- "conntrack" connection tracking match support (NETFILTER_XT_MATCH_CONNTRACK) [Y/n/m/?] y
- "dccp" protocol match support (NETFILTER_XT_MATCH_DCCP) [N/m/y/?] (NEW) y
- "dscp" and "tos" match support (NETFILTER_XT_MATCH_DSCP) [N/m/y/?] (NEW) y
- "esp" match support (NETFILTER_XT_MATCH_ESP) [N/m/y/?] (NEW) y
- "hashlimit" match support (NETFILTER_XT_MATCH_HASHLIMIT) [N/m/y/?] (NEW) y
- "helper" match support (NETFILTER_XT_MATCH_HELPER) [N/m/y/?] (NEW) y
- "iprange" address range match support (NETFILTER_XT_MATCH_IPRANGE) [N/m/y/?] (NEW) y
- "length" match support (NETFILTER_XT_MATCH_LENGTH) [Y/n/m/?] y
- "limit" match support (NETFILTER_XT_MATCH_LIMIT) [N/m/y/?] (NEW) y
- "mac" address match support (NETFILTER_XT_MATCH_MAC) [N/m/y/?] (NEW) y
- "mark" match support (NETFILTER_XT_MATCH_MARK) [N/m/y/?] n
- "multiport" Multiple port match support (NETFILTER_XT_MATCH_MULTIPORT) [N/m/y/?] (NEW) y
- "owner" match support (NETFILTER_XT_MATCH_OWNER) [N/m/y/?] (NEW) y
- IPsec "policy" match support (NETFILTER_XT_MATCH_POLICY) [N/m/y/?] n
- "pkttype" packet type match support (NETFILTER_XT_MATCH_PKTTYPE) [N/m/y/?] (NEW) y
- "quota" match support (NETFILTER_XT_MATCH_QUOTA) [N/m/y/?] (NEW) y
- "rateest" match support (NETFILTER_XT_MATCH_RATEEST) [N/m/y/?] (NEW) y
- "realm" match support (NETFILTER_XT_MATCH_REALM) [N/m/y/?] (NEW) y
- "recent" match support (NETFILTER_XT_MATCH_RECENT) [N/m/y/?] (NEW) y
- Enable obsolete /proc/net/ipt_recent (NETFILTER_XT_MATCH_RECENT_PROC_COMPAT) [N/y/?] (NEW) y
- "sctp" protocol match support (EXPERIMENTAL) (NETFILTER_XT_MATCH_SCTP) [N/m/y/?] (NEW) y
- "socket" match support (EXPERIMENTAL) (NETFILTER_XT_MATCH_SOCKET) [N/m/y/?] (NEW) y
- "state" match support (NETFILTER_XT_MATCH_STATE) [Y/n/m/?] y
- "statistic" match support (NETFILTER_XT_MATCH_STATISTIC) [N/m/y/?] (NEW) y
- "string" match support (NETFILTER_XT_MATCH_STRING) [N/m/y/?] (NEW) y
- "tcpmss" match support (NETFILTER_XT_MATCH_TCPMSS) [N/m/y/?] (NEW) y
- "time" match support (NETFILTER_XT_MATCH_TIME) [N/m/y/?] (NEW) y
- "u32" match support (NETFILTER_XT_MATCH_U32) [N/m/y/?] (NEW) y
- *
- * IP: Netfilter Configuration
- *
- IPv4 connection tracking support (required for NAT) (NF_CONNTRACK_IPV4) [Y/n/m/?] y
- proc/sysctl compatibility with old connection tracking (NF_CONNTRACK_PROC_COMPAT) [N/y/?] n
- IP Userspace queueing via NETLINK (OBSOLETE) (IP_NF_QUEUE) [N/m/y/?] (NEW) y
- IP tables support (required for filtering/masq/NAT) (IP_NF_IPTABLES) [Y/n/m/?] y
- "addrtype" address type match support (IP_NF_MATCH_ADDRTYPE) [N/m/y/?] (NEW) y
- "ah" match support (IP_NF_MATCH_AH) [N/m/y/?] (NEW) y
- "ecn" match support (IP_NF_MATCH_ECN) [N/m/y/?] (NEW) y
- "ttl" match support (IP_NF_MATCH_TTL) [N/m/y/?] (NEW) y
- Packet filtering (IP_NF_FILTER) [Y/n/m/?] y
- REJECT target support (IP_NF_TARGET_REJECT) [Y/n/m/?] y
- LOG target support (IP_NF_TARGET_LOG) [N/m/y/?] n
- ULOG target support (IP_NF_TARGET_ULOG) [N/m/y/?] n
- Full NAT (NF_NAT) [Y/n/m/?] y
- MASQUERADE target support (IP_NF_TARGET_MASQUERADE) [Y/n/m/?] y
- NETMAP target support (IP_NF_TARGET_NETMAP) [N/m/y/?] (NEW) y
- REDIRECT target support (IP_NF_TARGET_REDIRECT) [N/m/y/?] (NEW) y
- Basic SNMP-ALG support (NF_NAT_SNMP_BASIC) [N/m/y/?] (NEW) y
- Packet mangling (IP_NF_MANGLE) [Y/n/m/?] y
- CLUSTERIP target support (EXPERIMENTAL) (IP_NF_TARGET_CLUSTERIP) [N/m/y/?] (NEW) y
- ECN target support (IP_NF_TARGET_ECN) [N/m/y/?] (NEW) y
- TTL target support (IP_NF_TARGET_TTL) [N/m/y/?] (NEW) y
- raw table support (required for NOTRACK/TRACE) (IP_NF_RAW) [N/m/y/?] (NEW) y
- Security table (IP_NF_SECURITY) [N/m/y/?] (NEW) y
- ARP tables support (IP_NF_ARPTABLES) [N/m/y/?] (NEW) y
- ARP packet filtering (IP_NF_ARPFILTER) [N/m/y/?] (NEW) y
- ARP payload mangling (IP_NF_ARP_MANGLE) [N/m/y/?] (NEW) y
- *
- * Restart config...
- *
- *
- * Core Netfilter Configuration
- *
- Netfilter NFQUEUE over NFNETLINK interface (NETFILTER_NETLINK_QUEUE) [Y/n/m/?] y
- Netfilter LOG over NFNETLINK interface (NETFILTER_NETLINK_LOG) [N/m/y/?] n
- Netfilter connection tracking support (NF_CONNTRACK) [Y/n/m/?] y
- Connection tracking flow accounting (NF_CT_ACCT) [Y/?] y
- Connection mark tracking support (NF_CONNTRACK_MARK) [Y/?] y
- Connection tracking events (NF_CONNTRACK_EVENTS) [Y/n/?] y
- DCCP protocol connection tracking support (EXPERIMENTAL) (NF_CT_PROTO_DCCP) [Y/n/m/?] y
- SCTP protocol connection tracking support (EXPERIMENTAL) (NF_CT_PROTO_SCTP) [Y/n/m/?] y
- UDP-Lite protocol connection tracking support (NF_CT_PROTO_UDPLITE) [Y/n/m/?] y
- Amanda backup protocol support (NF_CONNTRACK_AMANDA) [Y/n/m/?] y
- FTP protocol support (NF_CONNTRACK_FTP) [Y/n/m/?] y
- H.323 protocol support (NF_CONNTRACK_H323) [Y/n/m/?] y
- IRC protocol support (NF_CONNTRACK_IRC) [N/m/y/?] n
- NetBIOS name service protocol support (NF_CONNTRACK_NETBIOS_NS) [Y/n/m/?] y
- PPtP protocol support (NF_CONNTRACK_PPTP) [Y/n/m/?] y
- SANE protocol support (EXPERIMENTAL) (NF_CONNTRACK_SANE) [Y/n/m/?] y
- SIP protocol support (NF_CONNTRACK_SIP) [Y/n/m/?] y
- TFTP protocol support (NF_CONNTRACK_TFTP) [Y/n/m/?] y
- Connection tracking netlink interface (NF_CT_NETLINK) [N/m/y/?] n
- Transparent proxying support (EXPERIMENTAL) (NETFILTER_TPROXY) [Y/n/m/?] y
- Netfilter Xtables support (required for ip_tables) (NETFILTER_XTABLES) [Y/?] y
- "CLASSIFY" target support (NETFILTER_XT_TARGET_CLASSIFY) [Y/n/m/?] y
- "CONNMARK" target support (NETFILTER_XT_TARGET_CONNMARK) [Y/n/m/?] y
- "DSCP" and "TOS" target support (NETFILTER_XT_TARGET_DSCP) [Y/n/m/?] y
- "MARK" target support (NETFILTER_XT_TARGET_MARK) [N/m/y/?] n
- "NFLOG" target support (NETFILTER_XT_TARGET_NFLOG) [N/m/y/?] n
- "NFQUEUE" target Support (NETFILTER_XT_TARGET_NFQUEUE) [Y/n/m/?] y
- "NOTRACK" target support (NETFILTER_XT_TARGET_NOTRACK) [N/m/y/?] (NEW) y
- "RATEEST" target support (NETFILTER_XT_TARGET_RATEEST) [Y/?] y
- "TPROXY" target support (EXPERIMENTAL) (NETFILTER_XT_TARGET_TPROXY) [Y/n/m/?] y
- "TRACE" target support (NETFILTER_XT_TARGET_TRACE) [N/m/y/?] (NEW) y
- "TCPMSS" target support (NETFILTER_XT_TARGET_TCPMSS) [N/m/y/?] n
- "TCPOPTSTRIP" target support (EXPERIMENTAL) (NETFILTER_XT_TARGET_TCPOPTSTRIP) [Y/n/m/?] y
- "comment" match support (NETFILTER_XT_MATCH_COMMENT) [Y/n/m/?] y
- "connbytes" per-connection counter match support (NETFILTER_XT_MATCH_CONNBYTES) [Y/n/m/?] y
- "connlimit" match support" (NETFILTER_XT_MATCH_CONNLIMIT) [Y/n/m/?] y
- "connmark" connection mark match support (NETFILTER_XT_MATCH_CONNMARK) [Y/n/m/?] y
- "conntrack" connection tracking match support (NETFILTER_XT_MATCH_CONNTRACK) [Y/n/m/?] y
- "dccp" protocol match support (NETFILTER_XT_MATCH_DCCP) [Y/n/m/?] y
- "dscp" and "tos" match support (NETFILTER_XT_MATCH_DSCP) [Y/n/m/?] y
- "esp" match support (NETFILTER_XT_MATCH_ESP) [Y/n/m/?] y
- "hashlimit" match support (NETFILTER_XT_MATCH_HASHLIMIT) [Y/n/m/?] y
- "helper" match support (NETFILTER_XT_MATCH_HELPER) [Y/n/m/?] y
- "iprange" address range match support (NETFILTER_XT_MATCH_IPRANGE) [Y/n/m/?] y
- "length" match support (NETFILTER_XT_MATCH_LENGTH) [Y/n/m/?] y
- "limit" match support (NETFILTER_XT_MATCH_LIMIT) [Y/n/m/?] y
- "mac" address match support (NETFILTER_XT_MATCH_MAC) [Y/n/m/?] y
- "mark" match support (NETFILTER_XT_MATCH_MARK) [N/m/y/?] n
- "multiport" Multiple port match support (NETFILTER_XT_MATCH_MULTIPORT) [Y/n/m/?] y
- "owner" match support (NETFILTER_XT_MATCH_OWNER) [Y/n/m/?] y
- IPsec "policy" match support (NETFILTER_XT_MATCH_POLICY) [N/m/y/?] n
- "pkttype" packet type match support (NETFILTER_XT_MATCH_PKTTYPE) [Y/n/m/?] y
- "quota" match support (NETFILTER_XT_MATCH_QUOTA) [Y/n/m/?] y
- "rateest" match support (NETFILTER_XT_MATCH_RATEEST) [Y/n/m/?] y
- "realm" match support (NETFILTER_XT_MATCH_REALM) [Y/n/m/?] y
- "recent" match support (NETFILTER_XT_MATCH_RECENT) [Y/n/m/?] y
- Enable obsolete /proc/net/ipt_recent (NETFILTER_XT_MATCH_RECENT_PROC_COMPAT) [Y/n/?] y
- "sctp" protocol match support (EXPERIMENTAL) (NETFILTER_XT_MATCH_SCTP) [Y/n/m/?] y
- "socket" match support (EXPERIMENTAL) (NETFILTER_XT_MATCH_SOCKET) [Y/n/m/?] y
- "state" match support (NETFILTER_XT_MATCH_STATE) [Y/n/m/?] y
- "statistic" match support (NETFILTER_XT_MATCH_STATISTIC) [Y/n/m/?] y
- "string" match support (NETFILTER_XT_MATCH_STRING) [Y/n/m/?] y
- "tcpmss" match support (NETFILTER_XT_MATCH_TCPMSS) [Y/n/m/?] y
- "time" match support (NETFILTER_XT_MATCH_TIME) [Y/n/m/?] y
- "u32" match support (NETFILTER_XT_MATCH_U32) [Y/n/m/?] y