iptables \ -w \ -A FJ-vnet0 \ -p sctp \ -m mac \ --mac-source 01:02:03:04:05:06 \ --destination 10.1.2.3/32 \ -m dscp \ --dscp 2 \ -m conntrack \ --ctstate NEW,ESTABLISHED \ -j RETURN iptables \ -w \ -A FP-vnet0 \ -p sctp \ --source 10.1.2.3/32 \ -m dscp \ --dscp 2 \ -m conntrack \ --ctstate ESTABLISHED \ -j ACCEPT iptables \ -w \ -A HJ-vnet0 \ -p sctp \ -m mac \ --mac-source 01:02:03:04:05:06 \ --destination 10.1.2.3/32 \ -m dscp \ --dscp 2 \ -m conntrack \ --ctstate NEW,ESTABLISHED \ -j RETURN iptables \ -w \ -A FJ-vnet0 \ -p sctp \ --destination 10.1.2.3/32 \ -m dscp \ --dscp 33 \ --dport 20:21 \ --sport 100:1111 \ -m conntrack \ --ctstate ESTABLISHED \ -j RETURN iptables \ -w \ -A FP-vnet0 \ -p sctp \ -m mac \ --mac-source 01:02:03:04:05:06 \ --source 10.1.2.3/32 \ -m dscp \ --dscp 33 \ --sport 20:21 \ --dport 100:1111 \ -m conntrack \ --ctstate NEW,ESTABLISHED \ -j ACCEPT iptables \ -w \ -A HJ-vnet0 \ -p sctp \ --destination 10.1.2.3/32 \ -m dscp \ --dscp 33 \ --dport 20:21 \ --sport 100:1111 \ -m conntrack \ --ctstate ESTABLISHED \ -j RETURN iptables \ -w \ -A FJ-vnet0 \ -p sctp \ --destination 10.1.2.3/32 \ -m dscp \ --dscp 63 \ --dport 255:256 \ --sport 65535:65535 \ -m conntrack \ --ctstate ESTABLISHED \ -j RETURN iptables \ -w \ -A FP-vnet0 \ -p sctp \ -m mac \ --mac-source 01:02:03:04:05:06 \ --source 10.1.2.3/32 \ -m dscp \ --dscp 63 \ --sport 255:256 \ --dport 65535:65535 \ -m conntrack \ --ctstate NEW,ESTABLISHED \ -j ACCEPT iptables \ -w \ -A HJ-vnet0 \ -p sctp \ --destination 10.1.2.3/32 \ -m dscp \ --dscp 63 \ --dport 255:256 \ --sport 65535:65535 \ -m conntrack \ --ctstate ESTABLISHED \ -j RETURN