--protocol -p proto protocol: by number or name, eg. `tcp' --source -s address[/mask][...] source specification --destination -d address[/mask][...] destination specification --in-interface -i input name[+] network interface name ([+] for wildcard) --jump -j target target for rule (may load target extension) --goto -g chain jump to chain with no return --out-interface -o output name[+] network interface name ([+] for wildcard) --table -t table table to manipulate (default: `filter') --line-numbers print line numbers when listing --fragment -f match second or further fragments only