How do I port forward all devices except for a few?

nice, now I have two working ways to do it. Which one is better is preference because both do the same thing and are just written differently. This is helpful for people looking for an answer to this question or trying to learn iptables

I think I'll put both on my config file and comment out the one I won't use (just in case I change my mind)

Disable or remove tcp intercept for method below
then add this to /etc/firewall.user

