Disclaimer
Packet filtering is something I’ve always hard a hard time getting my head around. Not the basics; that’s easy
enough. It’s just the incredible level of detail, the difficulty of keeping it all in your head at once.
And then, of course, there are all the different flavors: ipfw, ipfilters, ipchains, and now iptables. It gets more
than a little confusing, and I’ve never taken the time for more than a cursory look at any of them.