In latest iptables SVN, the command: iptables -A foo -p tcp -m multiport --dport 45,47 -m multiport --sport 45:48 ends up with mangled results of: ... multiport sports multiport sports tcp spts:45:48 Since at present, iptables can only handle one match of a given type per rule. The below patch makes sure we disallow more than one. This closes bugzilla #447 Phil