Книга: Iptables Tutorial 1.2.2
The comment match is used to add comments inside the iptables ruleset and the kernel. This can make it much easier to understand your ruleset and to ease debugging. For example, you could add comments documenting which bash function added specific sets of rules to netfilter, and why. It should be noted that this isn't actually a match. The comment match is loaded using the -m comment keywords. At this point the following options will be available.
Table 10-10. Comment match options
|Example||iptables -A INPUT -m comment --comment "A comment"|
|Explanation||The --comment option specifies the comment to actually add to the rule in kernel. The comment can be a maximum of 256 characters.|