In IP chains, the input chain applies to all datagrams received by the host, irrespective of whether they are destined for the local host or routed to some other host.
Additionally, rather than having to remember and use the hexadecimal value, you may specify the TOS bits using the more friendly mnemonics listed in the upcoming table.
Prevent datagram routing with invalid source addresses.
If your firewall supports a World Wide Web proxy, their telnet connection will always be answered by the proxy and will allow only http requests to pass.

Character negates the rule!