Une base pourrait être la suivante, à adapter :
[code]-N input_accept
-A input_accept -j LOG --log-prefix "INPUT ACCEPT "
-A input_accept -j ACCEPT
-N input_drop
-A input_drop -j LOG --log-prefix "INPUT DROP "
-A input_drop -j DROP
-N output_accept
-A output_accept -j LOG --log-prefix "OUTPUT ACCEPT "
-A output_accept -j ACCEPT
-N output_drop
-A output_drop -j LOG --log-prefix "OUTPUT DROP "
-A output_drop -j DROP
-N forward_accept
-A forward_accept -j LOG --log-prefix "FORWARD ACCEPT "
-A forward_accept -j ACCEPT
-N forward_drop
-A forward_drop -j LOG --log-prefix "FORWARD DROP "
-A forward_drop -j DROP
-A INPUT […] -j input_accept
-A INPUT […] -j input_drop
-A OUTPUT […] -j output_accept
-A OUTPUT […] -j output_drop
-A FORWARD […] -j forward_accept
-A FORWARD […] -j forward_drop[/code]