对进入本机的包含porn,两个字的数据包进行限制
sudo iptables -I INPUT 1 -p tcp -m string --string "porn" --algo bm -j REJECT
查看规则
sudo iptables -t filter -L --line-numbers
Chain INPUT (policy ACCEPT)
num target prot opt source destination
1 REJECT tcp -- anywhere anywhere STRING match "porn" ALGO name bm TO 65535 reject-with icmp-port-unreachable
现在用baidu进行搜索 porn,为何包含porn的网页仍旧可以打开?