Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # iptables-save
- # Generated by iptables-save v1.4.21 on Thu Mar 23 13:17:05 2017
- *raw
- :PREROUTING ACCEPT [14901444:15508075362]
- :OUTPUT ACCEPT [12093557:3566031252]
- :cali-OUTPUT - [0:0]
- :cali-PREROUTING - [0:0]
- :cali-failsafe-in - [0:0]
- :cali-failsafe-out - [0:0]
- :cali-from-host-endpoint - [0:0]
- :cali-pi-k8s-policy-no-match - [0:0]
- :cali-po-k8s-policy-no-match - [0:0]
- :cali-to-host-endpoint - [0:0]
- -A PREROUTING -m comment --comment "cali:6gwbT8clXdHdC1b1" -j cali-PREROUTING
- -A OUTPUT -m comment --comment "cali:tVnHkvAo15HuiPy0" -j cali-OUTPUT
- -A cali-OUTPUT -m comment --comment "cali:38nOqDjL6rORZtSl" -j MARK --set-xmark 0x0/0x7000000
- -A cali-OUTPUT -m comment --comment "cali:mDDUhMDnNdaIUtPr" -j cali-to-host-endpoint
- -A cali-OUTPUT -m comment --comment "cali:qxtWla1G8uqJMI9B" -m mark --mark 0x1000000/0x1000000 -j ACCEPT
- -A cali-PREROUTING -m comment --comment "cali:x4XbVMc5P_kNXnTy" -j MARK --set-xmark 0x0/0x7000000
- -A cali-PREROUTING -i cali+ -m comment --comment "cali:fQeZek80kVOPa0xO" -j MARK --set-xmark 0x4000000/0x4000000
- -A cali-PREROUTING -m comment --comment "cali:xp3NolkIpulCQL_G" -m mark --mark 0x0/0x4000000 -j cali-from-host-endpoint
- -A cali-PREROUTING -m comment --comment "cali:fbdE50A0BiINbNiA" -m mark --mark 0x1000000/0x1000000 -j ACCEPT
- -A cali-failsafe-in -p tcp -m comment --comment "cali:wWFQM43tJU7wwnFZ" -m multiport --dports 22 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:73bZKoyDfOpFwC2T" -m multiport --dports 2379 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:QMFuWo6o-d9yOpNm" -m multiport --dports 2380 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:Kup7QkrsdmfGX0uL" -m multiport --dports 4001 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:xYYr5PEqDf_Pqfkv" -m multiport --dports 7001 -j ACCEPT
- -A cali-pi-k8s-policy-no-match -m comment --comment "cali:eXR8WKtGQfKPd5zm" -j MARK --set-xmark 0x2000000/0x2000000
- -A cali-pi-k8s-policy-no-match -m comment --comment "cali:J7UwAp2kUUNYDEbZ" -m mark --mark 0x2000000/0x2000000 -j RETURN
- -A cali-po-k8s-policy-no-match -m comment --comment "cali:M1MvnGSuWnBDoJxY" -j MARK --set-xmark 0x2000000/0x2000000
- -A cali-po-k8s-policy-no-match -m comment --comment "cali:srq_4spRBeZ7r-5T" -m mark --mark 0x2000000/0x2000000 -j RETURN
- COMMIT
- # Completed on Thu Mar 23 13:17:05 2017
- # Generated by iptables-save v1.4.21 on Thu Mar 23 13:17:05 2017
- *filter
- :INPUT ACCEPT [2:120]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION - [0:0]
- :KUBE-FIREWALL - [0:0]
- :KUBE-SERVICES - [0:0]
- :cali-FORWARD - [0:0]
- :cali-INPUT - [0:0]
- :cali-OUTPUT - [0:0]
- :cali-failsafe-in - [0:0]
- :cali-failsafe-out - [0:0]
- :cali-from-host-endpoint - [0:0]
- :cali-from-wl-dispatch - [0:0]
- :cali-from-wl-dispatch-f - [0:0]
- :cali-fw-cali01894ffb609 - [0:0]
- :cali-fw-cali3e6931d032d - [0:0]
- :cali-fw-cali4f6359baa47 - [0:0]
- :cali-fw-calia47368f6a2f - [0:0]
- :cali-fw-calicceaa2f1590 - [0:0]
- :cali-fw-calif152a6fc379 - [0:0]
- :cali-fw-calif3f68101b1f - [0:0]
- :cali-pi-k8s-policy-no-match - [0:0]
- :cali-po-k8s-policy-no-match - [0:0]
- :cali-pri-_8RYwx-GzQkydyUOSQ3 - [0:0]
- :cali-pri-k8s_ns.ceph - [0:0]
- :cali-pri-k8s_ns.kube-system - [0:0]
- :cali-pro-_8RYwx-GzQkydyUOSQ3 - [0:0]
- :cali-pro-k8s_ns.ceph - [0:0]
- :cali-pro-k8s_ns.kube-system - [0:0]
- :cali-to-host-endpoint - [0:0]
- :cali-to-wl-dispatch - [0:0]
- :cali-to-wl-dispatch-f - [0:0]
- :cali-tw-cali01894ffb609 - [0:0]
- :cali-tw-cali3e6931d032d - [0:0]
- :cali-tw-cali4f6359baa47 - [0:0]
- :cali-tw-calia47368f6a2f - [0:0]
- :cali-tw-calicceaa2f1590 - [0:0]
- :cali-tw-calif152a6fc379 - [0:0]
- :cali-tw-calif3f68101b1f - [0:0]
- :cali-wl-to-host - [0:0]
- -A INPUT -m comment --comment "cali:Cz_u1IQiXIMmKD4c" -j cali-INPUT
- -A INPUT -j KUBE-FIREWALL
- -A FORWARD -m comment --comment "cali:wUHhoiAYhphO9Mso" -j cali-FORWARD
- -A FORWARD -j DOCKER-ISOLATION
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A OUTPUT -m comment --comment "cali:tVnHkvAo15HuiPy0" -j cali-OUTPUT
- -A OUTPUT -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A OUTPUT -j KUBE-FIREWALL
- -A DOCKER-ISOLATION -j RETURN
- -A KUBE-FIREWALL -m comment --comment "kubernetes firewall for dropping marked packets" -m mark --mark 0x8000/0x8000 -j DROP
- -A KUBE-SERVICES -d 10.3.0.116/32 -p tcp -m comment --comment "kube-system/kubernetes-dashboard: has no endpoints" -m tcp --dport 80 -j REJECT --reject-with icmp-port-unreachable
- -A KUBE-SERVICES -d 10.3.0.10/32 -p udp -m comment --comment "kube-system/kube-dns:dns has no endpoints" -m udp --dport 53 -j REJECT --reject-with icmp-port-unreachable
- -A KUBE-SERVICES -d 10.3.0.10/32 -p tcp -m comment --comment "kube-system/kube-dns:dns-tcp has no endpoints" -m tcp --dport 53 -j REJECT --reject-with icmp-port-unreachable
- -A cali-FORWARD -m comment --comment "cali:jxvuJjmmRV135nVu" -m mark --mark 0x1000000/0x1000000 -m conntrack --ctstate UNTRACKED -j ACCEPT
- -A cali-FORWARD -m comment --comment "cali:8YeDX9Z0tXyO0Sp8" -m conntrack --ctstate INVALID -j DROP
- -A cali-FORWARD -m comment --comment "cali:1GMSV-PhhZ8QbJg4" -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A cali-FORWARD -i cali+ -m comment --comment "cali:36TkoGXj9EF7Plkv" -j cali-from-wl-dispatch
- -A cali-FORWARD -o cali+ -m comment --comment "cali:URMhBRo8ugd8J8Yx" -j cali-to-wl-dispatch
- -A cali-FORWARD -i cali+ -m comment --comment "cali:FyhWsW08U3a5niLK" -j ACCEPT
- -A cali-FORWARD -o cali+ -m comment --comment "cali:G655uIfZuidj1gAw" -j ACCEPT
- -A cali-FORWARD -m comment --comment "cali:4GbueNC2iWajKnxO" -j MARK --set-xmark 0x0/0x7000000
- -A cali-FORWARD -m comment --comment "cali:bq3wVY3mkXk96NQP" -j cali-from-host-endpoint
- -A cali-FORWARD -m comment --comment "cali:G8sjbYXH5_QiYnBl" -j cali-to-host-endpoint
- -A cali-FORWARD -m comment --comment "cali:wYFYRdMhtSYCqKNm" -m comment --comment "Host endpoint policy accepted packet." -m mark --mark 0x1000000/0x1000000 -j ACCEPT
- -A cali-INPUT -m comment --comment "cali:46gVAqzWLjH8U4O2" -m mark --mark 0x1000000/0x1000000 -m conntrack --ctstate UNTRACKED -j ACCEPT
- -A cali-INPUT -m comment --comment "cali:5M2EkEm-RVlDLAfE" -m conntrack --ctstate INVALID -j DROP
- -A cali-INPUT -m comment --comment "cali:8ggYjLbFRX5Ap9Zj" -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A cali-INPUT -i cali+ -m comment --comment "cali:mA3ZJKi9nadUmYVF" -g cali-wl-to-host
- -A cali-INPUT -m comment --comment "cali:hI4IjifGj0fegLPE" -j MARK --set-xmark 0x0/0x7000000
- -A cali-INPUT -m comment --comment "cali:wdegoKfPlcmsZTOM" -j cali-from-host-endpoint
- -A cali-INPUT -m comment --comment "cali:r875VVc8vFk1f-ZA" -m comment --comment "Host endpoint policy accepted packet." -m mark --mark 0x1000000/0x1000000 -j ACCEPT
- -A cali-OUTPUT -m comment --comment "cali:FwFFCT8uDthhfgS7" -m mark --mark 0x1000000/0x1000000 -m conntrack --ctstate UNTRACKED -j ACCEPT
- -A cali-OUTPUT -m comment --comment "cali:KQN1p6BZgCGuApYk" -m conntrack --ctstate INVALID -j DROP
- -A cali-OUTPUT -m comment --comment "cali:ThMSEAwgeF4nAqRa" -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A cali-OUTPUT -o cali+ -m comment --comment "cali:0YpIH4BWIJL90PfX" -j RETURN
- -A cali-OUTPUT -m comment --comment "cali:sUIDpoFnawuqGYyG" -j MARK --set-xmark 0x0/0x7000000
- -A cali-OUTPUT -m comment --comment "cali:vQVzNX-dNxUnYjUT" -j cali-to-host-endpoint
- -A cali-OUTPUT -m comment --comment "cali:Ry2SAIVyda14xWHB" -m comment --comment "Host endpoint policy accepted packet." -m mark --mark 0x1000000/0x1000000 -j ACCEPT
- -A cali-failsafe-in -p tcp -m comment --comment "cali:wWFQM43tJU7wwnFZ" -m multiport --dports 22 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:73bZKoyDfOpFwC2T" -m multiport --dports 2379 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:QMFuWo6o-d9yOpNm" -m multiport --dports 2380 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:Kup7QkrsdmfGX0uL" -m multiport --dports 4001 -j ACCEPT
- -A cali-failsafe-out -p tcp -m comment --comment "cali:xYYr5PEqDf_Pqfkv" -m multiport --dports 7001 -j ACCEPT
- -A cali-from-wl-dispatch -i cali01894ffb609 -m comment --comment "cali:isI6nUt8Y0WEPoB9" -g cali-fw-cali01894ffb609
- -A cali-from-wl-dispatch -i cali3e6931d032d -m comment --comment "cali:S4przpeFJNHDSl9f" -g cali-fw-cali3e6931d032d
- -A cali-from-wl-dispatch -i cali4f6359baa47 -m comment --comment "cali:2keMPk-JZqUBR2G4" -g cali-fw-cali4f6359baa47
- -A cali-from-wl-dispatch -i calia47368f6a2f -m comment --comment "cali:-UlqAEm_nrt2kwGX" -g cali-fw-calia47368f6a2f
- -A cali-from-wl-dispatch -i calicceaa2f1590 -m comment --comment "cali:47InNUz85xzt2LH-" -g cali-fw-calicceaa2f1590
- -A cali-from-wl-dispatch -i calif+ -m comment --comment "cali:qAkWeYQwlxIeAgqe" -g cali-from-wl-dispatch-f
- -A cali-from-wl-dispatch -m comment --comment "cali:7CKiJ-4iPxHldSNe" -m comment --comment "Unknown interface" -j DROP
- -A cali-from-wl-dispatch-f -i calif152a6fc379 -m comment --comment "cali:EAiyywKGgzaikYvG" -g cali-fw-calif152a6fc379
- -A cali-from-wl-dispatch-f -i calif3f68101b1f -m comment --comment "cali:The3p7OKCvvFviBR" -g cali-fw-calif3f68101b1f
- -A cali-from-wl-dispatch-f -m comment --comment "cali:diyxRoksOWfe5MIG" -m comment --comment "Unknown interface" -j DROP
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:IR46k3tDVL6bztzx" -j MARK --set-xmark 0x0/0x1000000
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:s5mxv0N5kOuYF_M9" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:y09i32DwRLHHxu86" -m mark --mark 0x0/0x2000000 -j cali-po-k8s-policy-no-match
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:5ptRUA3zBKk9onHW" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:M5J2LA5P7LYAAn1X" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:dz3OWPL4kaYPvRJM" -j cali-pro-k8s_ns.ceph
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:m4U_kx-JbbDV3AOZ" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-cali01894ffb609 -m comment --comment "cali:UrrVbz3szRdn7ERf" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:iul9pwrAJ5KoZWZR" -j MARK --set-xmark 0x0/0x1000000
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:E8rTpuO6WOhiaAUF" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:Gc5An1ei49HsFWTu" -m mark --mark 0x0/0x2000000 -j cali-po-k8s-policy-no-match
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:MClBbWK7MM4PvpjL" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:TIqobWuEZGYv6216" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:WH5HfmiSKvFzRCjB" -j cali-pro-k8s_ns.kube-system
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:fo1iQZeQ_AFCmE6T" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-cali3e6931d032d -m comment --comment "cali:6tFimuXahmzbFZNV" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:IcMZnKmWH99K_p1G" -j MARK --set-xmark 0x0/0x1000000
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:phV1PSeOn61ysTdQ" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:8b7eGkBWzL5i7vX2" -m mark --mark 0x0/0x2000000 -j cali-po-k8s-policy-no-match
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:XbkJzwLhvt6xz3vS" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:Pggbx3Ai9_rmS-cm" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:LhJpizprRJwYFCuN" -j cali-pro-k8s_ns.kube-system
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:2hEwrqNE5sfbpmVh" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-cali4f6359baa47 -m comment --comment "cali:iaUZRMYlkPoBh18g" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:70fBIMTDYDE6QdGG" -j MARK --set-xmark 0x0/0x1000000
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:WvRuOZQqtp6KzM5G" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:2VZGI7ljgsyH7tlH" -m mark --mark 0x0/0x2000000 -j cali-po-k8s-policy-no-match
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:8QQRuPn4Anr_pE27" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:A7H9R1FiFsN4XNt5" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:KT1j69Oi3AuZtxp1" -j cali-pro-k8s_ns.kube-system
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:_NBh8bZM5LkI1MF8" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calia47368f6a2f -m comment --comment "cali:1QYbJp3tLbOZ7TyA" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:4VMt8i6uXOXLaXzq" -j MARK --set-xmark 0x0/0x1000000
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:xu9e_9Jfo2LMRSU9" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:i_nMSkmBSSumlNIZ" -m mark --mark 0x0/0x2000000 -j cali-po-k8s-policy-no-match
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:l7boG4sy6dQk_sw1" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:1E8V1eSUpBVi58jZ" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:EwCatqRYqNwDVi9I" -j cali-pro-_8RYwx-GzQkydyUOSQ3
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:cxF-c0LiaFRoLm07" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calicceaa2f1590 -m comment --comment "cali:i9djQdbmMYR8FC7h" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:mK4sSyhscbgYR-Ov" -j MARK --set-xmark 0x0/0x1000000
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:crDFkctr2IkG80zy" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:F2g_zUUXg6JdBFAS" -m mark --mark 0x0/0x2000000 -j cali-po-k8s-policy-no-match
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:i0cub1l25NnAkiik" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:ZvoejuT0MdQ8g5E9" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:PQScm-vlszbGXbDH" -j cali-pro-k8s_ns.kube-system
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:1jOsnDghSOcbSUg0" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calif152a6fc379 -m comment --comment "cali:N2LO9ghvGEIvTrUx" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:fcw3nPFYAz_x78Lr" -j MARK --set-xmark 0x0/0x1000000
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:RrUYuE27YJ7pDCfI" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:azdYB9wkLj3ZgNMP" -m mark --mark 0x0/0x2000000 -j cali-po-k8s-policy-no-match
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:JHkvobFYbFLxdnMH" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:Q7FT38i8lE9szYSd" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:w3yjfUiInXyg8vjL" -j cali-pro-k8s_ns.kube-system
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:LT0MnQGW2LK6USWs" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-fw-calif3f68101b1f -m comment --comment "cali:dXLmu9vYsoIeeR2P" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-pi-k8s-policy-no-match -m comment --comment "cali:eXR8WKtGQfKPd5zm" -j MARK --set-xmark 0x2000000/0x2000000
- -A cali-pi-k8s-policy-no-match -m comment --comment "cali:J7UwAp2kUUNYDEbZ" -m mark --mark 0x2000000/0x2000000 -j RETURN
- -A cali-po-k8s-policy-no-match -m comment --comment "cali:M1MvnGSuWnBDoJxY" -j MARK --set-xmark 0x2000000/0x2000000
- -A cali-po-k8s-policy-no-match -m comment --comment "cali:srq_4spRBeZ7r-5T" -m mark --mark 0x2000000/0x2000000 -j RETURN
- -A cali-pri-_8RYwx-GzQkydyUOSQ3 -m comment --comment "cali:Hdq93PPt97dIzXND" -j MARK --set-xmark 0x1000000/0x1000000
- -A cali-pri-_8RYwx-GzQkydyUOSQ3 -m comment --comment "cali:qYvzo5yLDMDLF5OQ" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-pri-k8s_ns.ceph -m comment --comment "cali:9jcfwv7PzhB_mi4D" -j MARK --set-xmark 0x1000000/0x1000000
- -A cali-pri-k8s_ns.ceph -m comment --comment "cali:xY2JC9Dj1r8DyhkM" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-pri-k8s_ns.kube-system -m comment --comment "cali:plMTf6GGo5FLt-zw" -j MARK --set-xmark 0x1000000/0x1000000
- -A cali-pri-k8s_ns.kube-system -m comment --comment "cali:d_ypsHpl3J96oOpx" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-pro-_8RYwx-GzQkydyUOSQ3 -m comment --comment "cali:8cptEHfAqYUSV2_B" -j MARK --set-xmark 0x1000000/0x1000000
- -A cali-pro-_8RYwx-GzQkydyUOSQ3 -m comment --comment "cali:YYU-kFjW-E8uk-Cj" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-pro-k8s_ns.ceph -m comment --comment "cali:VZFPtK7yz6IsDsX-" -j MARK --set-xmark 0x1000000/0x1000000
- -A cali-pro-k8s_ns.ceph -m comment --comment "cali:4JDPbmdSx5rP3CkN" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-pro-k8s_ns.kube-system -m comment --comment "cali:lDQGDZg5UANF5wIK" -j MARK --set-xmark 0x1000000/0x1000000
- -A cali-pro-k8s_ns.kube-system -m comment --comment "cali:wn_dnW-P0COWnhhy" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-to-wl-dispatch -o cali01894ffb609 -m comment --comment "cali:HEQ8MyspLcR1DJq7" -g cali-tw-cali01894ffb609
- -A cali-to-wl-dispatch -o cali3e6931d032d -m comment --comment "cali:V4GBJuDbO9V1HN-Y" -g cali-tw-cali3e6931d032d
- -A cali-to-wl-dispatch -o cali4f6359baa47 -m comment --comment "cali:jW91OvL0RyOj--2o" -g cali-tw-cali4f6359baa47
- -A cali-to-wl-dispatch -o calia47368f6a2f -m comment --comment "cali:_-18Z-DLKpLNqp_f" -g cali-tw-calia47368f6a2f
- -A cali-to-wl-dispatch -o calicceaa2f1590 -m comment --comment "cali:3chVGlGnK5RJ0dgK" -g cali-tw-calicceaa2f1590
- -A cali-to-wl-dispatch -o calif+ -m comment --comment "cali:zNxPvetFgq-SpxcY" -g cali-to-wl-dispatch-f
- -A cali-to-wl-dispatch -m comment --comment "cali:1UIo_ydw-tmvWoLq" -m comment --comment "Unknown interface" -j DROP
- -A cali-to-wl-dispatch-f -o calif152a6fc379 -m comment --comment "cali:uV-lSMpydVlyyTjo" -g cali-tw-calif152a6fc379
- -A cali-to-wl-dispatch-f -o calif3f68101b1f -m comment --comment "cali:t0uyQCEjkdY_O-gE" -g cali-tw-calif3f68101b1f
- -A cali-to-wl-dispatch-f -m comment --comment "cali:9yYC_193DtH35H6U" -m comment --comment "Unknown interface" -j DROP
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:Ol39SgbjIHDA_EFA" -j MARK --set-xmark 0x0/0x1000000
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:kGMS58UzUFWXtUxZ" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:vr793XEtlaf5du9d" -m mark --mark 0x0/0x2000000 -j cali-pi-k8s-policy-no-match
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:95w1KxLN11coWoXA" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:7MsVWbfvGNVHf8Xn" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:rXLK17az1qBDJk6J" -j cali-pri-k8s_ns.ceph
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:Y2yvo9bO0qjojCOT" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-cali01894ffb609 -m comment --comment "cali:2V2NpoZ17-jvPL6m" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:NPBXryE15YVGqWEK" -j MARK --set-xmark 0x0/0x1000000
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:uCGzE0_lJJVkEiah" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:gxz5Fl_tg5Kpr0Ud" -m mark --mark 0x0/0x2000000 -j cali-pi-k8s-policy-no-match
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:sgZswpKU-uxWCtNV" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:dbIO3rYwJnvsrs0I" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:40Z2VNPkQ8Tugxui" -j cali-pri-k8s_ns.kube-system
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:uWYb14ZXoPfCIV8u" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-cali3e6931d032d -m comment --comment "cali:h1FjbuI6rlSq3no4" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:L7G8ZsN6DbEbfZJr" -j MARK --set-xmark 0x0/0x1000000
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:HZQ3rNDsH_5oL7uZ" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:N8z7ROftW4bkmziH" -m mark --mark 0x0/0x2000000 -j cali-pi-k8s-policy-no-match
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:aoUIuAnb7x_on98y" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:qDkA6YfIWDlia9lp" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:1n2St00mBP438MVY" -j cali-pri-k8s_ns.kube-system
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:TQzSlkVUV1YSGo-r" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-cali4f6359baa47 -m comment --comment "cali:FO2ekbUsxKVqk1is" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:rhcR9dXKGdyoz1xD" -j MARK --set-xmark 0x0/0x1000000
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:WRzDf-gXpkYqkgip" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:xzuM0dvYOJwDCEbK" -m mark --mark 0x0/0x2000000 -j cali-pi-k8s-policy-no-match
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:fJwltuc-uUx5NHQE" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:q8WYoNNLxXj9RuZD" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:ICumnEYHKKOD3vk1" -j cali-pri-k8s_ns.kube-system
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:R-hxHlSMDjnx7GB-" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calia47368f6a2f -m comment --comment "cali:CC91toomv240aEfx" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:Cl1l1rb1XF2TrSNc" -j MARK --set-xmark 0x0/0x1000000
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:w3g3Hn24NQvu45-S" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:ij5f35cdLMSdrpnl" -m mark --mark 0x0/0x2000000 -j cali-pi-k8s-policy-no-match
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:KmJnOK9yZXBMD35R" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:LCDXgBQRqGUc4-kW" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:apRwKhDIJh5tOZ1S" -j cali-pri-_8RYwx-GzQkydyUOSQ3
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:VoQ_yRsibSem9jqC" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calicceaa2f1590 -m comment --comment "cali:A-x-RA7g_Za-1Apv" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:sb6kjm1_KC9mEpAb" -j MARK --set-xmark 0x0/0x1000000
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:cz61O8RFq4gIQ2YJ" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:d45YaLauJInyRo1M" -m mark --mark 0x0/0x2000000 -j cali-pi-k8s-policy-no-match
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:d1DK00JAFZc5rJHj" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:QTWj2lsYRVa_jL3B" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:Y1ci4m_endRGq0je" -j cali-pri-k8s_ns.kube-system
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:xGLPpFaOdpeC86DM" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calif152a6fc379 -m comment --comment "cali:6HYUe-Ifvf5fy05u" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:5Edx5GGUJA8zMRQB" -j MARK --set-xmark 0x0/0x1000000
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:7bnO-zcugvTGtbG0" -m comment --comment "Start of policies" -j MARK --set-xmark 0x0/0x2000000
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:1oyznZjzCg2zt_RS" -m mark --mark 0x0/0x2000000 -j cali-pi-k8s-policy-no-match
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:nROZ50Jo4ish7Lcp" -m comment --comment "Return if policy accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:np-DhFXUrJsuHSfh" -m comment --comment "Drop if no policies passed packet" -m mark --mark 0x0/0x2000000 -j DROP
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:-PSWrirhxc91NR5C" -j cali-pri-k8s_ns.kube-system
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:04w050Vi3ExJHbXj" -m comment --comment "Return if profile accepted" -m mark --mark 0x1000000/0x1000000 -j RETURN
- -A cali-tw-calif3f68101b1f -m comment --comment "cali:UACZLGLRF1Qu84fi" -m comment --comment "Drop if no profiles matched" -j DROP
- -A cali-wl-to-host -p udp -m comment --comment "cali:aEOMPPLgak2S0Lxs" -m multiport --sports 68 -m multiport --dports 67 -j ACCEPT
- -A cali-wl-to-host -p udp -m comment --comment "cali:SzR8ejPiuXtFMS8B" -m multiport --dports 53 -j ACCEPT
- -A cali-wl-to-host -m comment --comment "cali:MEmlbCdco0Fefcrw" -j cali-from-wl-dispatch
- -A cali-wl-to-host -m comment --comment "cali:3xIeqPkH_U4Pk0Cf" -m comment --comment "Configured DefaultEndpointToHostAction" -j DROP
- COMMIT
- # Completed on Thu Mar 23 13:17:05 2017
- # Generated by iptables-save v1.4.21 on Thu Mar 23 13:17:05 2017
- *nat
- :PREROUTING ACCEPT [2:120]
- :INPUT ACCEPT [2:120]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- :DOCKER - [0:0]
- :KUBE-MARK-DROP - [0:0]
- :KUBE-MARK-MASQ - [0:0]
- :KUBE-NODEPORTS - [0:0]
- :KUBE-POSTROUTING - [0:0]
- :KUBE-SEP-MYVNS4TYOGPJNVNR - [0:0]
- :KUBE-SEP-NSGWCYVM46HAWV73 - [0:0]
- :KUBE-SEP-PHU6AW6AGYEAERX7 - [0:0]
- :KUBE-SEP-QYFU6CFLNZUNWMCW - [0:0]
- :KUBE-SEP-XAU5BSYIZQXSE5IR - [0:0]
- :KUBE-SERVICES - [0:0]
- :KUBE-SVC-BJM46V3U5RZHCFRZ - [0:0]
- :KUBE-SVC-DHPNFOWDQUXNIZO5 - [0:0]
- :KUBE-SVC-ERIFXISQEP7F7OF4 - [0:0]
- :KUBE-SVC-JRXTEHDDTAFMSEAS - [0:0]
- :KUBE-SVC-NPX46M4PTMTKRN6Y - [0:0]
- :KUBE-SVC-Q6XJQ2I55QTBQCWT - [0:0]
- :KUBE-SVC-TCOU7JCQXEZGVUNU - [0:0]
- :KUBE-SVC-XGLOHA7QRQ3V22RZ - [0:0]
- :cali-OUTPUT - [0:0]
- :cali-POSTROUTING - [0:0]
- :cali-PREROUTING - [0:0]
- :cali-fip-dnat - [0:0]
- :cali-fip-snat - [0:0]
- :cali-nat-outgoing - [0:0]
- -A PREROUTING -m comment --comment "cali:6gwbT8clXdHdC1b1" -j cali-PREROUTING
- -A PREROUTING -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT -m comment --comment "cali:tVnHkvAo15HuiPy0" -j cali-OUTPUT
- -A OUTPUT -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -m comment --comment "cali:O3lYWMrLQYEMJtB5" -j cali-POSTROUTING
- -A POSTROUTING -m comment --comment "kubernetes postrouting rules" -j KUBE-POSTROUTING
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -s 10.2.0.0/16 -d 10.2.0.0/16 -j RETURN
- -A POSTROUTING -s 10.2.0.0/16 ! -d 224.0.0.0/4 -j MASQUERADE
- -A POSTROUTING ! -s 10.2.0.0/16 -d 10.2.0.0/16 -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A KUBE-MARK-DROP -j MARK --set-xmark 0x8000/0x8000
- -A KUBE-MARK-MASQ -j MARK --set-xmark 0x4000/0x4000
- -A KUBE-POSTROUTING -m comment --comment "kubernetes service traffic requiring SNAT" -m mark --mark 0x4000/0x4000 -j MASQUERADE
- -A KUBE-SEP-MYVNS4TYOGPJNVNR -s 192.168.1.2/32 -m comment --comment "default/kubernetes:https" -j KUBE-MARK-MASQ
- -A KUBE-SEP-MYVNS4TYOGPJNVNR -p tcp -m comment --comment "default/kubernetes:https" -m recent --set --name KUBE-SEP-MYVNS4TYOGPJNVNR --mask 255.255.255.255 --rsource -m tcp -j DNAT --to-destination 192.168.1.2:443
- -A KUBE-SEP-NSGWCYVM46HAWV73 -s 10.2.63.9/32 -m comment --comment "kube-system/heapster:" -j KUBE-MARK-MASQ
- -A KUBE-SEP-NSGWCYVM46HAWV73 -p tcp -m comment --comment "kube-system/heapster:" -m tcp -j DNAT --to-destination 10.2.63.9:8082
- -A KUBE-SEP-PHU6AW6AGYEAERX7 -s 10.2.63.2/32 -m comment --comment "kube-system/monitoring-influxdb:" -j KUBE-MARK-MASQ
- -A KUBE-SEP-PHU6AW6AGYEAERX7 -p tcp -m comment --comment "kube-system/monitoring-influxdb:" -m tcp -j DNAT --to-destination 10.2.63.2:8086
- -A KUBE-SEP-QYFU6CFLNZUNWMCW -s 10.2.63.3/32 -m comment --comment "nginx-ingress/default-http-backend:" -j KUBE-MARK-MASQ
- -A KUBE-SEP-QYFU6CFLNZUNWMCW -p tcp -m comment --comment "nginx-ingress/default-http-backend:" -m tcp -j DNAT --to-destination 10.2.63.3:8080
- -A KUBE-SEP-XAU5BSYIZQXSE5IR -s 10.2.63.3/32 -m comment --comment "kube-system/monitoring-grafana:" -j KUBE-MARK-MASQ
- -A KUBE-SEP-XAU5BSYIZQXSE5IR -p tcp -m comment --comment "kube-system/monitoring-grafana:" -m tcp -j DNAT --to-destination 10.2.63.3:3000
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.116/32 -p tcp -m comment --comment "kube-system/kubernetes-dashboard: cluster IP" -m tcp --dport 80 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.116/32 -p tcp -m comment --comment "kube-system/kubernetes-dashboard: cluster IP" -m tcp --dport 80 -j KUBE-SVC-XGLOHA7QRQ3V22RZ
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.187/32 -p tcp -m comment --comment "kube-system/monitoring-grafana: cluster IP" -m tcp --dport 80 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.187/32 -p tcp -m comment --comment "kube-system/monitoring-grafana: cluster IP" -m tcp --dport 80 -j KUBE-SVC-JRXTEHDDTAFMSEAS
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.214/32 -p tcp -m comment --comment "kube-system/monitoring-influxdb: cluster IP" -m tcp --dport 8086 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.214/32 -p tcp -m comment --comment "kube-system/monitoring-influxdb: cluster IP" -m tcp --dport 8086 -j KUBE-SVC-Q6XJQ2I55QTBQCWT
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.233/32 -p tcp -m comment --comment "nginx-ingress/default-http-backend: cluster IP" -m tcp --dport 80 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.233/32 -p tcp -m comment --comment "nginx-ingress/default-http-backend: cluster IP" -m tcp --dport 80 -j KUBE-SVC-DHPNFOWDQUXNIZO5
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.1/32 -p tcp -m comment --comment "default/kubernetes:https cluster IP" -m tcp --dport 443 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.1/32 -p tcp -m comment --comment "default/kubernetes:https cluster IP" -m tcp --dport 443 -j KUBE-SVC-NPX46M4PTMTKRN6Y
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.2/32 -p tcp -m comment --comment "kube-system/heapster: cluster IP" -m tcp --dport 80 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.2/32 -p tcp -m comment --comment "kube-system/heapster: cluster IP" -m tcp --dport 80 -j KUBE-SVC-BJM46V3U5RZHCFRZ
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.10/32 -p udp -m comment --comment "kube-system/kube-dns:dns cluster IP" -m udp --dport 53 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.10/32 -p udp -m comment --comment "kube-system/kube-dns:dns cluster IP" -m udp --dport 53 -j KUBE-SVC-TCOU7JCQXEZGVUNU
- -A KUBE-SERVICES ! -s 10.2.0.0/16 -d 10.3.0.10/32 -p tcp -m comment --comment "kube-system/kube-dns:dns-tcp cluster IP" -m tcp --dport 53 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 10.3.0.10/32 -p tcp -m comment --comment "kube-system/kube-dns:dns-tcp cluster IP" -m tcp --dport 53 -j KUBE-SVC-ERIFXISQEP7F7OF4
- -A KUBE-SERVICES -m comment --comment "kubernetes service nodeports; NOTE: this must be the last rule in this chain" -m addrtype --dst-type LOCAL -j KUBE-NODEPORTS
- -A KUBE-SVC-BJM46V3U5RZHCFRZ -m comment --comment "kube-system/heapster:" -j KUBE-SEP-NSGWCYVM46HAWV73
- -A KUBE-SVC-DHPNFOWDQUXNIZO5 -m comment --comment "nginx-ingress/default-http-backend:" -j KUBE-SEP-QYFU6CFLNZUNWMCW
- -A KUBE-SVC-JRXTEHDDTAFMSEAS -m comment --comment "kube-system/monitoring-grafana:" -j KUBE-SEP-XAU5BSYIZQXSE5IR
- -A KUBE-SVC-NPX46M4PTMTKRN6Y -m comment --comment "default/kubernetes:https" -m recent --rcheck --seconds 10800 --reap --name KUBE-SEP-MYVNS4TYOGPJNVNR --mask 255.255.255.255 --rsource -j KUBE-SEP-MYVNS4TYOGPJNVNR
- -A KUBE-SVC-NPX46M4PTMTKRN6Y -m comment --comment "default/kubernetes:https" -j KUBE-SEP-MYVNS4TYOGPJNVNR
- -A KUBE-SVC-Q6XJQ2I55QTBQCWT -m comment --comment "kube-system/monitoring-influxdb:" -j KUBE-SEP-PHU6AW6AGYEAERX7
- -A cali-OUTPUT -m comment --comment "cali:GBTAv2p5CwevEyJm" -j cali-fip-dnat
- -A cali-POSTROUTING -m comment --comment "cali:Z-c7XtVd2Bq7s_hA" -j cali-fip-snat
- -A cali-POSTROUTING -m comment --comment "cali:nYKhEzDlr11Jccal" -j cali-nat-outgoing
- -A cali-PREROUTING -m comment --comment "cali:r6XmIziWUJsdOK6Z" -j cali-fip-dnat
- COMMIT
- # Completed on Thu Mar 23 13:17:05 2017
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement