Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- berlioz ~ # iptables -S FORWARD
- -P FORWARD ACCEPT
- -A FORWARD -j nova-filter-top
- -A FORWARD -j nova-network-FORWARD
- -A FORWARD -j nova-compute-FORWARD
- -A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
- -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
- -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement