Iptables can use extended packet matching modules.
These are loaded in two ways: implicitly, when -p or --protocol is specified,or with the -m or --match options, followed by the matching module name; after these, various extra command line options become available, depending on the specific module.
You can specify multiple extended match modules in one line, and you can use the -h or --help options after the module has been specified to receive help specific to that module.
This module matches the 8 bits of Type of Service field in the IP header (ie. including the precedence bits).
tos --tos
The argument is either a standard name,(use ‘iptables -m tos -h’ to see the list), or a numeric value to match.
-m length --length 100
阅读(1337) | 评论(0) | 转发(0) |