+$IPT -t filter -A FORWARD -m state --state INVALID -j DROP
+$IPT -t filter -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
+
+if [ -d /etc/firewall.d ]; then
+ for fw in /etc/firewall.d/??*; do
+ [ -x $fw ] && $fw
+ done
+fi
+
+# defaults
+