{"group":"xtables_addons","uses":[{"description":"ACCOUNT target is a high performance accounting system for large local networks","group":"xtables_addons","isdefault":false,"use":"account"},{"description":"match a packet by its source or destination Autonomous System Number","group":"xtables_addons","isdefault":false,"use":"asn"},{"description":"CHAOS target causes confusion on the other end by doing odd things with incoming packets","group":"xtables_addons","isdefault":false,"use":"chaos"},{"description":"matches if a specific condition variable is (un)set","group":"xtables_addons","isdefault":false,"use":"condition"},{"description":"DELUDE target will reply to a SYN packet with SYN-ACK, and to all other packets with an RST","group":"xtables_addons","isdefault":false,"use":"delude"},{"description":"DHCPMAC target\/match in conjunction with ebtables can be used to completely change all MAC addresses from and to a VMware-based virtual machine","group":"xtables_addons","isdefault":false,"use":"dhcpmac"},{"description":"DNETMAP target allows dynamic two-way 1:1 mapping of IPv4 subnets","group":"xtables_addons","isdefault":false,"use":"dnetmap"},{"description":"ECHO target sends back all packets it received","group":"xtables_addons","isdefault":false,"use":"echo"},{"description":"matches a rate limit based on a fuzzy logic controller (FLC)","group":"xtables_addons","isdefault":false,"use":"fuzzy"},{"description":"match a packet by its source or destination country","group":"xtables_addons","isdefault":false,"use":"geoip"},{"description":"match packets based on grsecurity RBAC status","group":"xtables_addons","isdefault":false,"use":"gradm"},{"description":"match allows to check interface states","group":"xtables_addons","isdefault":false,"use":"iface"},{"description":"IPMARK target allows mark a received packet basing on its IP address","group":"xtables_addons","isdefault":false,"use":"ipmark"},{"description":"matches certain packets in P2P flows","group":"xtables_addons","isdefault":false,"use":"ipp2p"},{"description":"match against a set of IPv4 header options","group":"xtables_addons","isdefault":false,"use":"ipv4options"},{"description":"matches the length of a packet against a specific value or range of values","group":"xtables_addons","isdefault":false,"use":"length2"},{"description":"LOGMARK target will log packet and connection marks to syslog","group":"xtables_addons","isdefault":false,"use":"logmark"},{"description":"match detects simple low-level scan attemps based upon the packet's contents","group":"xtables_addons","isdefault":false,"use":"lscan"},{"description":"match implements so-called \"port knocking\", a stealthy system for network authentication","group":"xtables_addons","isdefault":false,"use":"pknock"},{"description":"modifies the protocol number in IP packet header","group":"xtables_addons","isdefault":false,"use":"proto"},{"description":"match attempts to detect TCP and UDP port scans (derived from Solar Designer's scanlogd)","group":"xtables_addons","isdefault":false,"use":"psd"},{"description":"match implements a named counter which can be increased or decreased on a per-match basis","group":"xtables_addons","isdefault":false,"use":"quota2"},{"description":"SYSRQ target allows to remotely trigger sysrq on the local machine over the network","group":"xtables_addons","isdefault":false,"use":"sysrq"},{"description":"TARPIT target captures and holds incoming TCP connections using no local per-connection resources","group":"xtables_addons","isdefault":false,"use":"tarpit"}]}