Parece-me que é por causa de uma nova versão do iptables que saiu em outubro. -m state --state
foi obsoleto em favor de -m conntrack --ctstate
. Portanto, "A correspondência de estado é obsoleta. Use conntrack em vez disso."
'conntrack' está na minha página man (1.4.14, que é não a mais nova):
conntrack This module, when combined with connection tracking, allows access to the connection tracking state for this packet/connection.
[!] --ctstate statelist statelist is a comma separated list of the connection states to match. Possible states are listed below.
[...]
States for --ctstate:
INVALID meaning that the packet is associated with no known connection
NEW meaning that the packet has started a new connection, or otherwise associated with a connection which has not seen packets in both directions, and
ESTABLISHED meaning that the packet is associated with a connection which has seen packets in both directions,
RELATED meaning that the packet is starting a new connection, but is associated with an existing connection, such as an FTP data transfer, or an ICMP error.
[...]
Obrigado pelo aviso, BTW.