I see rules in my "iptables -S" dump like

-A IN_work_allow -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT

But how do I create one ?  I cannot find any documentation on "state" or "ctstate" setting.

Thanks.
Dan White | d_e_white@icloud.com
------------------------------------------------
“Sometimes I think the surest sign that intelligent life exists elsewhere in the universe is that none of it has tried to contact us.”  (Bill Waterson: Calvin & Hobbes)