# STOP the daemon before you modify these -- otherwise the old iptables
# rules won't be torn down!
-# What TCP ports to capture? This can be a number or a range with ':'
-# e.g. 0:65535 to captures all ports
+# which netfilter userspace queue to use
+# which user account
+# where to chroot
+# which ports should tcpcrypt try to engage on?
+# see the multiport extension in iptables-extensions(8) for how to specify
+# set exactly one of OMIT_PORTS or ONLY_PORTS: