disable: if checked, not execute filter.policy: choose deny,reject,accept or none. if logging only, select none. -- deny: neglect packet -- reject: reply icmp destinaton port unreachable packetdevice: choose filtering network interface.(output interface if forward.)loggin: if checked,logging to kernel log.direction: filtering traffic direction to interfaceprotocol: if you'll define ports ,you must choose tcp or udp. if you select syn,it specify syn packet of tcp.src addr: source address of packets.you can define network. you define one address type, never include space. you must input any address. example ) 192.168.0.1 , 192.168.0.2/32 , 192.168.0.2/24 10.0.0.0/255.0.0.0 , 0/0 (all address)src port: source port number is delimit by comma Caution: never include space. example ) 20,21,25,80,8000:10000 (':' express range)" example ) !20 ( "!" is except. don't use multi port. range is ok.)dest addr: destnation address of packets. see 'src addr'.dest port: destnation port of packets. see 'src port'.