Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.0 on Sat Oct 23 17:15:07 2021
- *nat
- :PREROUTING ACCEPT [33:1768]
- :INPUT ACCEPT [33:1768]
- :OUTPUT ACCEPT [1:60]
- :POSTROUTING ACCEPT [1:60]
- :DOCKER - [0:0]
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A DOCKER -i docker0 -j RETURN
- -A DOCKER -i br-cec684d51ec9 -j RETURN
- COMMIT
- # Completed on Sat Oct 23 17:15:07 2021
- # Generated by iptables-save v1.6.0 on Sat Oct 23 17:15:07 2021
- *mangle
- :PREROUTING ACCEPT [59360:33829563]
- :INPUT ACCEPT [59360:33829563]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [58450:12397936]
- :POSTROUTING ACCEPT [58000:12320012]
- -A POSTROUTING -p tcp -m tcp --sport 8666 -j TTL --ttl-set 2
- -A POSTROUTING -p tcp -m tcp --sport 8666 -j TTL --ttl-set 2
- -A POSTROUTING -p tcp -m tcp --sport 8666 -j TTL --ttl-set 2
- COMMIT
- # Completed on Sat Oct 23 17:15:07 2021
- # Generated by iptables-save v1.6.0 on Sat Oct 23 17:15:07 2021
- *filter
- :INPUT ACCEPT [3282:270345]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [2262:290766]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- -A INPUT -p tcp -m multiport --dports 80,443 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 8666 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-ISOLATION-STAGE-1
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A FORWARD -o br-cec684d51ec9 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o br-cec684d51ec9 -j DOCKER
- -A FORWARD -i br-cec684d51ec9 ! -o br-cec684d51ec9 -j ACCEPT
- -A FORWARD -i br-cec684d51ec9 -o br-cec684d51ec9 -j ACCEPT
- -A OUTPUT -p icmp -j DROP
- -A OUTPUT -p icmp -m icmp --icmp-type 8 -j DROP
- -A OUTPUT -p tcp -m multiport --dports 80,443 -m conntrack --ctstate ESTABLISHED -j ACCEPT
- -A OUTPUT -p tcp -m tcp --sport 8666 -m conntrack --ctstate ESTABLISHED -j ACCEPT
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i br-cec684d51ec9 ! -o br-cec684d51ec9 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -j RETURN
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o br-cec684d51ec9 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -j RETURN
- -A DOCKER-USER -j RETURN
- COMMIT
- # Completed on Sat Oct 23 17:15:07 2021
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement