I met a interesting problem today... First, I setup a iptable policy like this:
iptables -A INPUT -p tcp --dport