I want to ban already established connections.
Default iptables rules generated by firewalld
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -j INPUT_direct
How to insert rule before -j ACCEPT
?
Or how to move INPUT_direct to top?
Or how to remove conntrack rule?