*filter :INPUT DROP :FORWARD DROP :OUTPUT ACCEPT -A INPUT -m set --match-set nasties src -j DROP -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -p icmp --icmp-type ping -j ACCEPT -A INPUT -p tcp --dport 22 -j ACCEPT -A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT -A INPUT -p tcp --dport 5665 -j ACCEPT COMMIT