1iptables-translate -A INPUT -p sctp --dport 80 -j DROP 2nft 'add rule ip filter INPUT sctp dport 80 counter drop' 3 4iptables-translate -A INPUT -p sctp --sport 50 -j DROP 5nft 'add rule ip filter INPUT sctp sport 50 counter drop' 6 7iptables-translate -A INPUT -p sctp ! --dport 80 -j DROP 8nft 'add rule ip filter INPUT sctp dport != 80 counter drop' 9 10iptables-translate -A INPUT -p sctp ! --sport 50 -j DROP 11nft 'add rule ip filter INPUT sctp sport != 50 counter drop' 12 13iptables-translate -A INPUT -p sctp --sport 80:100 -j ACCEPT 14nft 'add rule ip filter INPUT sctp sport 80-100 counter accept' 15 16iptables-translate -A INPUT -p sctp --dport 50:56 -j ACCEPT 17nft 'add rule ip filter INPUT sctp dport 50-56 counter accept' 18 19iptables-translate -A INPUT -p sctp ! --sport 80:100 -j ACCEPT 20nft 'add rule ip filter INPUT sctp sport != 80-100 counter accept' 21 22iptables-translate -A INPUT -p sctp ! --dport 50:56 -j ACCEPT 23nft 'add rule ip filter INPUT sctp dport != 50-56 counter accept' 24 25iptables-translate -A INPUT -p sctp --dport 80 --sport 50 -j ACCEPT 26nft 'add rule ip filter INPUT sctp sport 50 sctp dport 80 counter accept' 27 28iptables-translate -A INPUT -p sctp --dport 80:100 --sport 50 -j ACCEPT 29nft 'add rule ip filter INPUT sctp sport 50 sctp dport 80-100 counter accept' 30 31iptables-translate -A INPUT -p sctp --dport 80 --sport 50:55 -j ACCEPT 32nft 'add rule ip filter INPUT sctp sport 50-55 sctp dport 80 counter accept' 33 34iptables-translate -A INPUT -p sctp ! --dport 80:100 --sport 50 -j ACCEPT 35nft 'add rule ip filter INPUT sctp sport 50 sctp dport != 80-100 counter accept' 36 37iptables-translate -A INPUT -p sctp --dport 80 ! --sport 50:55 -j ACCEPT 38nft 'add rule ip filter INPUT sctp sport != 50-55 sctp dport 80 counter accept' 39 40iptables-translate -A INPUT -p sctp --chunk-types all INIT,DATA:iUbE,SACK,ABORT:T -j ACCEPT 41nft 'add rule ip filter INPUT sctp chunk data flags & 0xf == 0x5 sctp chunk init exists sctp chunk sack exists sctp chunk abort flags & 0x1 == 0x1 counter accept' 42 43iptables-translate -A INPUT -p sctp --chunk-types only SHUTDOWN_COMPLETE -j ACCEPT 44nft 'add rule ip filter INPUT sctp chunk data missing sctp chunk init missing sctp chunk init-ack missing sctp chunk sack missing sctp chunk heartbeat missing sctp chunk heartbeat-ack missing sctp chunk abort missing sctp chunk shutdown missing sctp chunk shutdown-ack missing sctp chunk error missing sctp chunk cookie-echo missing sctp chunk cookie-ack missing sctp chunk ecne missing sctp chunk cwr missing sctp chunk shutdown-complete exists sctp chunk i-data missing sctp chunk re-config missing sctp chunk pad missing sctp chunk asconf missing sctp chunk asconf-ack missing sctp chunk forward-tsn missing sctp chunk i-forward-tsn missing counter accept' 45