you missed stateful inspection, which iptables doesn't do the best job of but its better than IPchains..that does nothing at all