Quote Originally Posted by cariboo907 View Post
A firewall really doesn't do anything on a default installation, as there are no ports open to the outside world, and if you are behind a router, it's a belt + suspenders type of activity.

it's just like the poster earlier that tried to block Opera from accessing the Internet. Web browsers and many other programs use random high ports for out going connections, so it's pretty hard to block a port if you don't know which one it is using, and it changes every time you use a program, have a look at this example:

netstat -tn
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State      
tcp        0      0     ESTABLISHED
tcp        0      0        ESTABLISHED
tcp        0      0         TIME_WAIT  
tcp        1      0          CLOSE_WAIT 
tcp        1      0          CLOSE_WAIT
I've bolded the outgoing ports, these change every time a program is opened.
For outgoing connections it is easier to block the dport rather then the source port.

sudo iptables -A OUTPUT --dport 80 -j DROP
Will block opera (and other web browsers) =)