Four statuses
New
Established
Related
Invalid
NEW (a connection B is called the NEW package before B does not reply)
ESTABLISHED)
Once a and B are connected, there is a communication stream in both directions, and other packages associated with this append are regarded as in the ESTABLISHED status.
RELATED (the successful connection between a and B is called RELATED when multiple RELATED connections are generated by this connection)
The RELATED package is the packages that start new connections but are RELATED to the existing connections. The RELATED status can be used to adjust the composition of multiple connection protocols (such as ftp 21 for communication 20 data transmission) and error packets RELATED to existing connections (such as ICMP error packets RELATED to existing connections)
INVALID (INVALID package will not be discarded automatically, so write a policy to discard it)
Invalid package because this package will not be automatically discarded, You need to insert appropriate rules and set a chain policy so that these packages can be correctly processed.
Allow intranet connection to the Internet and deny Internet connection to the Intranet
Iptables-a input-m state -- state established, related-j accept
Iptables-a input-m state -- state new, invalid-j drop