Basically you tell it what packets to drop. In your rules you says something like "all packets from network 172.30.0.0 get dropped" and every time a packet comes in the kernel compares it to all the ...
一些您可能无法访问的结果已被隐去。
显示无法访问的结果一些您可能无法访问的结果已被隐去。
显示无法访问的结果