The man/-h pages for multiport don't document that you can use inversion. This can be confusing, since multiport uses '! --port x' instead of '--dport ! x' like tcp/udp. This closes bugzilla #143 Phil