Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.0 on Thu Sep 19 00:01:42 2019
- *nat
- :PREROUTING ACCEPT [137:9170]
- :INPUT ACCEPT [43:1650]
- :OUTPUT ACCEPT [42:2621]
- :POSTROUTING ACCEPT [76:4729]
- :DOCKER - [0:0]
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 30033 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 10022 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 10011 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p udp -m udp --dport 9987 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.4/32 -d 172.17.0.4/32 -p tcp -m tcp --dport 30034 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.4/32 -d 172.17.0.4/32 -p tcp -m tcp --dport 10023 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.4/32 -d 172.17.0.4/32 -p tcp -m tcp --dport 10012 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.4/32 -d 172.17.0.4/32 -p udp -m udp --dport 9988 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 30035 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 10024 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 10013 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p udp -m udp --dport 9989 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.6/32 -d 172.17.0.6/32 -p tcp -m tcp --dport 30036 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.6/32 -d 172.17.0.6/32 -p tcp -m tcp --dport 10025 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.6/32 -d 172.17.0.6/32 -p tcp -m tcp --dport 10014 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.6/32 -d 172.17.0.6/32 -p udp -m udp --dport 9990 -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 30033 -j DNAT --to-destination 172.17.0.3:30033
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10022 -j DNAT --to-destination 172.17.0.3:10022
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10011 -j DNAT --to-destination 172.17.0.3:10011
- -A DOCKER ! -i docker0 -p udp -m udp --dport 9987 -j DNAT --to-destination 172.17.0.3:9987
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 30034 -j DNAT --to-destination 172.17.0.4:30033
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10023 -j DNAT --to-destination 172.17.0.4:10022
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10012 -j DNAT --to-destination 172.17.0.4:10011
- -A DOCKER ! -i docker0 -p udp -m udp --dport 9988 -j DNAT --to-destination 172.17.0.4:9987
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 30035 -j DNAT --to-destination 172.17.0.2:30033
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10024 -j DNAT --to-destination 172.17.0.2:10022
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10013 -j DNAT --to-destination 172.17.0.2:10011
- -A DOCKER ! -i docker0 -p udp -m udp --dport 9989 -j DNAT --to-destination 172.17.0.2:9987
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 30036 -j DNAT --to-destination 172.17.0.6:30037
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10025 -j DNAT --to-destination 172.17.0.6:10027
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 10014 -j DNAT --to-destination 172.17.0.6:10015
- -A DOCKER ! -i docker0 -p udp -m udp --dport 9990 -j DNAT --to-destination 172.17.0.6:9991
- COMMIT
- # Completed on Thu Sep 19 00:01:42 2019
- # Generated by iptables-save v1.6.0 on Thu Sep 19 00:01:42 2019
- *filter
- :INPUT ACCEPT [31943:34440981]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [58954:25563291]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-ISOLATION-STAGE-1
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 30033 -j ACCEPT
- -A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10022 -j ACCEPT
- -A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10011 -j ACCEPT
- -A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p udp -m udp --dport 9987 -j ACCEPT
- -A DOCKER -d 172.17.0.4/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 30034 -j ACCEPT
- -A DOCKER -d 172.17.0.4/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10023 -j ACCEPT
- -A DOCKER -d 172.17.0.4/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10012 -j ACCEPT
- -A DOCKER -d 172.17.0.4/32 ! -i docker0 -o docker0 -p udp -m udp --dport 9988 -j ACCEPT
- -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 30035 -j ACCEPT
- -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10024 -j ACCEPT
- -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10013 -j ACCEPT
- -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p udp -m udp --dport 9990 -j ACCEPT
- -A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 30036 -j ACCEPT
- -A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10025 -j ACCEPT
- -A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 10014 -j ACCEPT
- -A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p udp -m udp --dport 9990 -j ACCEPT
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -j RETURN
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -j RETURN
- -A DOCKER-USER -j RETURN
- COMMIT
- # Completed on Thu Sep 19 00:01:42 2019
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement