I have these added:
-A INPUT -p tcp --dport 20900 -j ACCEPT
-A INPUT -p udp --dport 20900 -j ACCEPT
-A INPUT -p tcp --dport 5998 -j ACCEPT
-A INPUT -p tcp --dport 5999 -j ACCEPT
-A INPUT -p udp --dport 5998 -j ACCEPT
-A INPUT -p udp --dport 5999 -j ACCEPT
I haven't setup the zone stuff yet.
|