{
    # Find the current InboundUDP_$$ chain and create a new one.
    $OUT .=<<'EOF';
    OLD_InboundUDP=$(get_safe_id InboundUDP filter find)
    NEW_InboundUDP=$(get_safe_id InboundUDP filter new)
    /sbin/iptables --new-chain $NEW_InboundUDP
EOF
    $OUT .= "    /sbin/iptables --append \$NEW_InboundUDP \\! " .
	    "--destination \$OUTERNET --jump denylog\n";
}
