Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.0 on Mon Apr 24 21:09:50 2017
- *nat
- :PREROUTING ACCEPT [10949:900848]
- :INPUT ACCEPT [4860:174348]
- :OUTPUT ACCEPT [6676:731081]
- :POSTROUTING ACCEPT [6676:731081]
- :DOCKER - [0:0]
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -s 172.21.0.0/16 ! -o br-b676b1fd2bdc -j MASQUERADE
- -A POSTROUTING -s 172.19.0.0/16 ! -o br-4de25c9923c9 -j MASQUERADE
- -A POSTROUTING -s 172.20.0.0/16 ! -o br-d9707f66aa59 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 22 -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A DOCKER -i br-d9707f66aa59 -j RETURN
- -A DOCKER -i br-b676b1fd2bdc -j RETURN
- -A DOCKER -i br-4de25c9923c9 -j RETURN
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 22124 -j DNAT --to-destination 172.17.0.2:22
- COMMIT
- # Completed on Mon Apr 24 21:09:50 2017
- # Generated by iptables-save v1.6.0 on Mon Apr 24 21:09:50 2017
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- :Cid45457X4064.0 - [0:0]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION - [0:0]
- :In_RULE_0 - [0:0]
- :In_RULE_10 - [0:0]
- :In_RULE_4 - [0:0]
- :In_RULE_5 - [0:0]
- :In_RULE_6 - [0:0]
- :In_RULE_7 - [0:0]
- :In_RULE_8 - [0:0]
- :In_RULE_9 - [0:0]
- :RULE_11 - [0:0]
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -s 176.31.100.25/32 -i eth0 -m state --state NEW -j In_RULE_0
- -A INPUT -i lo -m state --state NEW -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 0/0 -m state --state NEW -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 11/0 -m state --state NEW -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 11/1 -m state --state NEW -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
- -A INPUT -s 176.31.100.25/32 -m state --state NEW -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp -m multiport --dports 80,443 -m state --state NEW -j In_RULE_4
- -A INPUT -i eth0 -p tcp -m tcp --dport 8070:8099 -m state --state NEW -j In_RULE_5
- -A INPUT -i eth0 -p tcp -m tcp --dport 9987:9989 -m state --state NEW -j In_RULE_6
- -A INPUT -i eth0 -p tcp -m tcp --dport 64738 -m state --state NEW -j In_RULE_7
- -A INPUT -i eth0 -p tcp -m tcp --dport 22120:22129 -m state --state NEW -j In_RULE_8
- -A INPUT -i eth0 -p tcp -m tcp --sport 20 --dport 1024:65535 -m state --state NEW -j In_RULE_9
- -A INPUT -i eth0 -p tcp -m tcp -m multiport --dports 21,20 -m state --state NEW -j In_RULE_9
- -A INPUT -i eth0 -p tcp -m tcp --dport 3690 -m state --state NEW -j In_RULE_10
- -A INPUT -j RULE_11
- -A FORWARD -j DOCKER-ISOLATION
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A FORWARD -o br-b676b1fd2bdc -j DOCKER
- -A FORWARD -o br-b676b1fd2bdc -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i br-b676b1fd2bdc ! -o br-b676b1fd2bdc -j ACCEPT
- -A FORWARD -i br-b676b1fd2bdc -o br-b676b1fd2bdc -j ACCEPT
- -A FORWARD -o br-4de25c9923c9 -j DOCKER
- -A FORWARD -o br-4de25c9923c9 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i br-4de25c9923c9 ! -o br-4de25c9923c9 -j ACCEPT
- -A FORWARD -i br-4de25c9923c9 -o br-4de25c9923c9 -j ACCEPT
- -A FORWARD -o br-d9707f66aa59 -j DOCKER
- -A FORWARD -o br-d9707f66aa59 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i br-d9707f66aa59 ! -o br-d9707f66aa59 -j ACCEPT
- -A FORWARD -i br-d9707f66aa59 -o br-d9707f66aa59 -j ACCEPT
- -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 176.31.100.25/32 -i eth0 -m state --state NEW -j In_RULE_0
- -A FORWARD -j RULE_11
- -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A OUTPUT -o lo -m state --state NEW -j ACCEPT
- -A OUTPUT -d 176.31.100.25/32 -m state --state NEW -j Cid45457X4064.0
- -A OUTPUT -m state --state NEW -j ACCEPT
- -A OUTPUT -j RULE_11
- -A Cid45457X4064.0 -p icmp -m icmp --icmp-type 3 -j ACCEPT
- -A Cid45457X4064.0 -p icmp -m icmp --icmp-type 0/0 -j ACCEPT
- -A Cid45457X4064.0 -p icmp -m icmp --icmp-type 8/0 -j ACCEPT
- -A Cid45457X4064.0 -p icmp -m icmp --icmp-type 11/0 -j ACCEPT
- -A Cid45457X4064.0 -p icmp -m icmp --icmp-type 11/1 -j ACCEPT
- -A Cid45457X4064.0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A DOCKER-ISOLATION -i br-4de25c9923c9 -o docker0 -j DROP
- -A DOCKER-ISOLATION -i docker0 -o br-4de25c9923c9 -j DROP
- -A DOCKER-ISOLATION -i br-d9707f66aa59 -o docker0 -j DROP
- -A DOCKER-ISOLATION -i docker0 -o br-d9707f66aa59 -j DROP
- -A DOCKER-ISOLATION -i br-b676b1fd2bdc -o docker0 -j DROP
- -A DOCKER-ISOLATION -i docker0 -o br-b676b1fd2bdc -j DROP
- -A DOCKER-ISOLATION -i br-b676b1fd2bdc -o br-d9707f66aa59 -j DROP
- -A DOCKER-ISOLATION -i br-d9707f66aa59 -o br-b676b1fd2bdc -j DROP
- -A DOCKER-ISOLATION -i br-4de25c9923c9 -o br-d9707f66aa59 -j DROP
- -A DOCKER-ISOLATION -i br-d9707f66aa59 -o br-4de25c9923c9 -j DROP
- -A DOCKER-ISOLATION -i br-4de25c9923c9 -o br-b676b1fd2bdc -j DROP
- -A DOCKER-ISOLATION -i br-b676b1fd2bdc -o br-4de25c9923c9 -j DROP
- -A DOCKER-ISOLATION -j RETURN
- -A In_RULE_0 -j LOG --log-prefix "RULE 0 -- DENY " --log-level 6
- -A In_RULE_0 -j DROP
- -A In_RULE_10 -j LOG --log-prefix "RULE 10 -- ACCEPT " --log-level 6
- -A In_RULE_10 -j ACCEPT
- -A In_RULE_4 -j LOG --log-prefix "RULE 4 -- ACCEPT " --log-level 6
- -A In_RULE_4 -j ACCEPT
- -A In_RULE_5 -j LOG --log-prefix "RULE 5 -- ACCEPT " --log-level 6
- -A In_RULE_5 -j ACCEPT
- -A In_RULE_6 -j LOG --log-prefix "RULE 6 -- ACCEPT " --log-level 6
- -A In_RULE_6 -j ACCEPT
- -A In_RULE_7 -j LOG --log-prefix "RULE 7 -- ACCEPT " --log-level 6
- -A In_RULE_7 -j ACCEPT
- -A In_RULE_8 -j LOG --log-prefix "RULE 8 -- ACCEPT " --log-level 6
- -A In_RULE_8 -j ACCEPT
- -A In_RULE_9 -j LOG --log-prefix "RULE 9 -- ACCEPT " --log-level 6
- -A In_RULE_9 -j ACCEPT
- -A RULE_11 -j LOG --log-prefix "RULE 11 -- DENY " --log-level 6
- -A RULE_11 -j DROP
- COMMIT
- # Completed on Mon Apr 24 21:09:50 2017
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement