Сабж.
Трафик жрет:
IGMP (46 bytes) from 1.10.10.1 to 224.0.0.1 on eth0
# Generated by iptables-save v1.3.2 on Wed Oct 5 18:44:39 2005
*nat
:PREROUTING ACCEPT [671:18788]
:POSTROUTING ACCEPT [772:47819]
:OUTPUT ACCEPT [772:47819]
COMMIT
# Completed on Wed Oct 5 18:44:39 2005
# Generated by iptables-save v1.3.2 on Wed Oct 5 18:44:39 2005
*mangle
:PREROUTING ACCEPT [13804:10721646]
:INPUT ACCEPT [13804:10721646]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [11541:2937810]
:POSTROUTING ACCEPT [11541:2937810]
COMMIT
# Completed on Wed Oct 5 18:44:39 2005
# Generated by iptables-save v1.3.2 on Wed Oct 5 18:44:39 2005
*filter
:INPUT DROP [15:420]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p udp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p igmp -j DROP
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -p icmp -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 32768:65535 -j ACCEPT
-A OUTPUT -p udp -m udp --sport 32768:65535 -j ACCEPT
-A OUTPUT -p igmp -j DROP
COMMIT
# Completed on Wed Oct 5 18:44:39 2005
Как видите DROP есть на него:
-A OUTPUT -p igmp -j DROP
-A INPUT -p igmp -j DROP