Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- iptables -S -t nat
- -P PREROUTING ACCEPT
- -P INPUT ACCEPT
- -P OUTPUT ACCEPT
- -P POSTROUTING ACCEPT
- -N DOCKER
- -N OUTPUT_direct
- -N POSTROUTING_ZONES
- -N POSTROUTING_ZONES_SOURCE
- -N POSTROUTING_direct
- -N POST_public
- -N POST_public_allow
- -N POST_public_deny
- -N POST_public_log
- -N PREROUTING_ZONES
- -N PREROUTING_ZONES_SOURCE
- -N PREROUTING_direct
- -N PRE_public
- -N PRE_public_allow
- -N PRE_public_deny
- -N PRE_public_log
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT -j OUTPUT_direct
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -j POSTROUTING_direct
- -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- -A POSTROUTING -j POSTROUTING_ZONES
- -A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 5559 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.5/32 -d 172.17.0.5/32 -p tcp -m tcp --dport 27017 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.6/32 -d 172.17.0.6/32 -p tcp -m tcp --dport 5559 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.7/32 -d 172.17.0.7/32 -p tcp -m tcp --dport 5559 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.8/32 -d 172.17.0.8/32 -p tcp -m tcp --dport 5559 -j MASQUERADE
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 5555 -j DNAT --to-destination 172.17.0.3:5559
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 29019 -j DNAT --to-destination 172.17.0.5:27017
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 5557 -j DNAT --to-destination 172.17.0.6:5559
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 5558 -j DNAT --to-destination 172.17.0.7:5559
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 5559 -j DNAT --to-destination 172.17.0.8:5559
- -A POSTROUTING_ZONES -o eth0 -g POST_public
- -A POSTROUTING_ZONES -g POST_public
- -A POST_public -j POST_public_log
- -A POST_public -j POST_public_deny
- -A POST_public -j POST_public_allow
- -A POST_public_allow ! -i lo -j MASQUERADE
- -A PREROUTING_ZONES -i eth0 -g PRE_public
- -A PREROUTING_ZONES -g PRE_public
- -A PRE_public -j PRE_public_log
- -A PRE_public -j PRE_public_deny
- -A PRE_public -j PRE_public_allow
Advertisement
Add Comment
Please, Sign In to add comment