Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.0 on Fri Jan 15 17:31:19 2021
- *raw
- :PREROUTING ACCEPT [270:30339]
- :OUTPUT ACCEPT [253:43767]
- -A PREROUTING -d 169.254.20.10/32 -p udp -m udp --dport 53 -j NOTRACK
- -A PREROUTING -d 169.254.20.10/32 -p tcp -m tcp --dport 53 -j NOTRACK
- -A OUTPUT -s 169.254.20.10/32 -p udp -m udp --sport 53 -j NOTRACK
- -A OUTPUT -s 169.254.20.10/32 -p tcp -m tcp --sport 53 -j NOTRACK
- COMMIT
- # Completed on Fri Jan 15 17:31:19 2021
- # Generated by iptables-save v1.6.0 on Fri Jan 15 17:31:19 2021
- *nat
- :PREROUTING ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :OUTPUT ACCEPT [39:2340]
- :POSTROUTING ACCEPT [29:1740]
- :DOCKER - [0:0]
- :KUBE-MARK-DROP - [0:0]
- :KUBE-MARK-MASQ - [0:0]
- :KUBE-NODEPORTS - [0:0]
- :KUBE-POSTROUTING - [0:0]
- :KUBE-SEP-2HA5TZC4IRJHZTCK - [0:0]
- :KUBE-SEP-422ARSXEMT65DMO3 - [0:0]
- :KUBE-SEP-7LER77DVHYCXPSW7 - [0:0]
- :KUBE-SEP-AFCCFOKTEURLEF4M - [0:0]
- :KUBE-SEP-ALQTRHCKDRO63XYJ - [0:0]
- :KUBE-SEP-AXYSTSVUFD26FOJT - [0:0]
- :KUBE-SEP-BJBTFEPEVIQ5DWH7 - [0:0]
- :KUBE-SEP-E26B7IBY35UOOL5X - [0:0]
- :KUBE-SEP-E5AJ7SMD4N6IABHF - [0:0]
- :KUBE-SEP-ENBFHXAAZ3V67RLH - [0:0]
- :KUBE-SEP-ESSITLOJZJMNLUID - [0:0]
- :KUBE-SEP-GXHHKOPUDMXRKSXD - [0:0]
- :KUBE-SEP-I6T2TXN3D36S6GQI - [0:0]
- :KUBE-SEP-J4YWKECJNT5JIGX4 - [0:0]
- :KUBE-SEP-L7UULNY5HKKVVJNM - [0:0]
- :KUBE-SEP-LAHH7QPLEAC4IYW6 - [0:0]
- :KUBE-SEP-ONANHDFYT3LJDUUS - [0:0]
- :KUBE-SEP-QAMAEZD76Z4XHHC3 - [0:0]
- :KUBE-SEP-RQQBQZBLXJLIS4XR - [0:0]
- :KUBE-SEP-T5JK32PCSUGR3PRV - [0:0]
- :KUBE-SEP-TV3U67EFPF6RYKGW - [0:0]
- :KUBE-SEP-UNHMTT7BF3FQAUBW - [0:0]
- :KUBE-SEP-WGFTNBDV6SMMGVGC - [0:0]
- :KUBE-SEP-ZYPAAOI74HAROTEV - [0:0]
- :KUBE-SERVICES - [0:0]
- :KUBE-SVC-ERIFXISQEP7F7OF4 - [0:0]
- :KUBE-SVC-GRVIJZ6QHJZF73YT - [0:0]
- :KUBE-SVC-IFO32E4YIRUTZPGJ - [0:0]
- :KUBE-SVC-JD5MR3NA4I4DYORP - [0:0]
- :KUBE-SVC-JV6T3AKDQP7UY5J7 - [0:0]
- :KUBE-SVC-NPX46M4PTMTKRN6Y - [0:0]
- :KUBE-SVC-TCOU7JCQXEZGVUNU - [0:0]
- :KUBE-SVC-U7X4VZNLLMJVC6JR - [0:0]
- -A PREROUTING -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -m comment --comment "kubernetes postrouting rules" -j KUBE-POSTROUTING
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING ! -d 100.64.0.0/10 -m comment --comment "kubenet: SNAT for outbound traffic from cluster" -m addrtype ! --dst-type LOCAL -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A KUBE-MARK-DROP -j MARK --set-xmark 0x8000/0x8000
- -A KUBE-MARK-MASQ -j MARK --set-xmark 0x4000/0x4000
- -A KUBE-NODEPORTS -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:http" -m tcp --dport 30393 -j KUBE-MARK-MASQ
- -A KUBE-NODEPORTS -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:http" -m tcp --dport 30393 -j KUBE-SVC-U7X4VZNLLMJVC6JR
- -A KUBE-NODEPORTS -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:https" -m tcp --dport 30674 -j KUBE-MARK-MASQ
- -A KUBE-NODEPORTS -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:https" -m tcp --dport 30674 -j KUBE-SVC-JV6T3AKDQP7UY5J7
- -A KUBE-POSTROUTING -m comment --comment "kubernetes service traffic requiring SNAT" -m mark --mark 0x4000/0x4000 -j MASQUERADE
- -A KUBE-SEP-2HA5TZC4IRJHZTCK -s 100.96.3.8/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-2HA5TZC4IRJHZTCK -p tcp -m tcp -j DNAT --to-destination 100.96.3.8:80
- -A KUBE-SEP-422ARSXEMT65DMO3 -s 100.96.3.5/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-422ARSXEMT65DMO3 -p tcp -m tcp -j DNAT --to-destination 100.96.3.5:80
- -A KUBE-SEP-7LER77DVHYCXPSW7 -s 100.96.3.11/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-7LER77DVHYCXPSW7 -p tcp -m tcp -j DNAT --to-destination 100.96.3.11:80
- -A KUBE-SEP-AFCCFOKTEURLEF4M -s 100.96.3.4/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-AFCCFOKTEURLEF4M -p tcp -m recent --set --name KUBE-SEP-AFCCFOKTEURLEF4M --mask 255.255.255.255 --rsource -m tcp -j DNAT --to-destination 100.96.3.4:9090
- -A KUBE-SEP-ALQTRHCKDRO63XYJ -s 100.96.3.10/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-ALQTRHCKDRO63XYJ -p tcp -m tcp -j DNAT --to-destination 100.96.3.10:80
- -A KUBE-SEP-AXYSTSVUFD26FOJT -s 100.96.3.10/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-AXYSTSVUFD26FOJT -p tcp -m tcp -j DNAT --to-destination 100.96.3.10:80
- -A KUBE-SEP-BJBTFEPEVIQ5DWH7 -s 100.96.3.14/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-BJBTFEPEVIQ5DWH7 -p tcp -m tcp -j DNAT --to-destination 100.96.3.14:53
- -A KUBE-SEP-E26B7IBY35UOOL5X -s 100.96.3.14/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-E26B7IBY35UOOL5X -p tcp -m tcp -j DNAT --to-destination 100.96.3.14:10054
- -A KUBE-SEP-E5AJ7SMD4N6IABHF -s 100.96.3.13/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-E5AJ7SMD4N6IABHF -p udp -m udp -j DNAT --to-destination 100.96.3.13:53
- -A KUBE-SEP-ENBFHXAAZ3V67RLH -s 172.20.48.195/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-ENBFHXAAZ3V67RLH -p tcp -m tcp -j DNAT --to-destination 172.20.48.195:443
- -A KUBE-SEP-ESSITLOJZJMNLUID -s 100.96.3.7/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-ESSITLOJZJMNLUID -p tcp -m tcp -j DNAT --to-destination 100.96.3.7:6443
- -A KUBE-SEP-GXHHKOPUDMXRKSXD -s 100.96.3.5/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-GXHHKOPUDMXRKSXD -p tcp -m tcp -j DNAT --to-destination 100.96.3.5:80
- -A KUBE-SEP-I6T2TXN3D36S6GQI -s 100.96.3.8/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-I6T2TXN3D36S6GQI -p tcp -m tcp -j DNAT --to-destination 100.96.3.8:80
- -A KUBE-SEP-J4YWKECJNT5JIGX4 -s 100.96.3.13/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-J4YWKECJNT5JIGX4 -p tcp -m tcp -j DNAT --to-destination 100.96.3.13:10054
- -A KUBE-SEP-L7UULNY5HKKVVJNM -s 100.96.3.11/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-L7UULNY5HKKVVJNM -p tcp -m tcp -j DNAT --to-destination 100.96.3.11:80
- -A KUBE-SEP-LAHH7QPLEAC4IYW6 -s 100.96.3.2/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-LAHH7QPLEAC4IYW6 -p tcp -m tcp -j DNAT --to-destination 100.96.3.2:80
- -A KUBE-SEP-ONANHDFYT3LJDUUS -s 100.96.3.9/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-ONANHDFYT3LJDUUS -p tcp -m recent --set --name KUBE-SEP-ONANHDFYT3LJDUUS --mask 255.255.255.255 --rsource -m tcp -j DNAT --to-destination 100.96.3.9:9090
- -A KUBE-SEP-QAMAEZD76Z4XHHC3 -s 100.96.3.2/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-QAMAEZD76Z4XHHC3 -p tcp -m tcp -j DNAT --to-destination 100.96.3.2:80
- -A KUBE-SEP-RQQBQZBLXJLIS4XR -s 100.96.3.3/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-RQQBQZBLXJLIS4XR -p tcp -m tcp -j DNAT --to-destination 100.96.3.3:80
- -A KUBE-SEP-T5JK32PCSUGR3PRV -s 172.20.118.103/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-T5JK32PCSUGR3PRV -p tcp -m tcp -j DNAT --to-destination 172.20.118.103:443
- -A KUBE-SEP-TV3U67EFPF6RYKGW -s 100.96.3.14/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-TV3U67EFPF6RYKGW -p udp -m udp -j DNAT --to-destination 100.96.3.14:53
- -A KUBE-SEP-UNHMTT7BF3FQAUBW -s 172.20.84.163/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-UNHMTT7BF3FQAUBW -p tcp -m tcp -j DNAT --to-destination 172.20.84.163:443
- -A KUBE-SEP-WGFTNBDV6SMMGVGC -s 100.96.3.3/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-WGFTNBDV6SMMGVGC -p tcp -m tcp -j DNAT --to-destination 100.96.3.3:80
- -A KUBE-SEP-ZYPAAOI74HAROTEV -s 100.96.3.13/32 -j KUBE-MARK-MASQ
- -A KUBE-SEP-ZYPAAOI74HAROTEV -p tcp -m tcp -j DNAT --to-destination 100.96.3.13:53
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.64.0.10/32 -p tcp -m comment --comment "kube-system/kube-dns:dns-tcp cluster IP" -m tcp --dport 53 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.64.0.10/32 -p tcp -m comment --comment "kube-system/kube-dns:dns-tcp cluster IP" -m tcp --dport 53 -j KUBE-SVC-ERIFXISQEP7F7OF4
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.64.0.10/32 -p tcp -m comment --comment "kube-system/kube-dns:metrics cluster IP" -m tcp --dport 10054 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.64.0.10/32 -p tcp -m comment --comment "kube-system/kube-dns:metrics cluster IP" -m tcp --dport 10054 -j KUBE-SVC-JD5MR3NA4I4DYORP
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.71.5.156/32 -p tcp -m comment --comment "monitoring/prometheus-k8s:web cluster IP" -m tcp --dport 9090 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.71.5.156/32 -p tcp -m comment --comment "monitoring/prometheus-k8s:web cluster IP" -m tcp --dport 9090 -j KUBE-SVC-IFO32E4YIRUTZPGJ
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.67.11.39/32 -p tcp -m comment --comment "monitoring/prometheus-adapter:https cluster IP" -m tcp --dport 443 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.67.11.39/32 -p tcp -m comment --comment "monitoring/prometheus-adapter:https cluster IP" -m tcp --dport 443 -j KUBE-SVC-GRVIJZ6QHJZF73YT
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.64.0.1/32 -p tcp -m comment --comment "default/kubernetes:https cluster IP" -m tcp --dport 443 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.64.0.1/32 -p tcp -m comment --comment "default/kubernetes:https cluster IP" -m tcp --dport 443 -j KUBE-SVC-NPX46M4PTMTKRN6Y
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.64.0.10/32 -p udp -m comment --comment "kube-system/kube-dns:dns cluster IP" -m udp --dport 53 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.64.0.10/32 -p udp -m comment --comment "kube-system/kube-dns:dns cluster IP" -m udp --dport 53 -j KUBE-SVC-TCOU7JCQXEZGVUNU
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.66.141.150/32 -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:http cluster IP" -m tcp --dport 80 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.66.141.150/32 -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:http cluster IP" -m tcp --dport 80 -j KUBE-SVC-U7X4VZNLLMJVC6JR
- -A KUBE-SERVICES ! -s 100.96.0.0/11 -d 100.66.141.150/32 -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:https cluster IP" -m tcp --dport 443 -j KUBE-MARK-MASQ
- -A KUBE-SERVICES -d 100.66.141.150/32 -p tcp -m comment --comment "ingress-nginx-ext/ingress-nginx-ext:https cluster IP" -m tcp --dport 443 -j KUBE-SVC-JV6T3AKDQP7UY5J7
- -A KUBE-SERVICES -m comment --comment "kubernetes service nodeports; NOTE: this must be the last rule in this chain" -m addrtype --dst-type LOCAL -j KUBE-NODEPORTS
- -A KUBE-SVC-ERIFXISQEP7F7OF4 -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-ZYPAAOI74HAROTEV
- -A KUBE-SVC-ERIFXISQEP7F7OF4 -j KUBE-SEP-BJBTFEPEVIQ5DWH7
- -A KUBE-SVC-GRVIJZ6QHJZF73YT -j KUBE-SEP-ESSITLOJZJMNLUID
- -A KUBE-SVC-IFO32E4YIRUTZPGJ -m recent --rcheck --seconds 10800 --reap --name KUBE-SEP-AFCCFOKTEURLEF4M --mask 255.255.255.255 --rsource -j KUBE-SEP-AFCCFOKTEURLEF4M
- -A KUBE-SVC-IFO32E4YIRUTZPGJ -m recent --rcheck --seconds 10800 --reap --name KUBE-SEP-ONANHDFYT3LJDUUS --mask 255.255.255.255 --rsource -j KUBE-SEP-ONANHDFYT3LJDUUS
- -A KUBE-SVC-IFO32E4YIRUTZPGJ -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-AFCCFOKTEURLEF4M
- -A KUBE-SVC-IFO32E4YIRUTZPGJ -j KUBE-SEP-ONANHDFYT3LJDUUS
- -A KUBE-SVC-JD5MR3NA4I4DYORP -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-J4YWKECJNT5JIGX4
- -A KUBE-SVC-JD5MR3NA4I4DYORP -j KUBE-SEP-E26B7IBY35UOOL5X
- -A KUBE-SVC-JV6T3AKDQP7UY5J7 -m statistic --mode random --probability 0.16667000018 -j KUBE-SEP-ALQTRHCKDRO63XYJ
- -A KUBE-SVC-JV6T3AKDQP7UY5J7 -m statistic --mode random --probability 0.20000000019 -j KUBE-SEP-7LER77DVHYCXPSW7
- -A KUBE-SVC-JV6T3AKDQP7UY5J7 -m statistic --mode random --probability 0.25000000000 -j KUBE-SEP-QAMAEZD76Z4XHHC3
- -A KUBE-SVC-JV6T3AKDQP7UY5J7 -m statistic --mode random --probability 0.33332999982 -j KUBE-SEP-WGFTNBDV6SMMGVGC
- -A KUBE-SVC-JV6T3AKDQP7UY5J7 -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-GXHHKOPUDMXRKSXD
- -A KUBE-SVC-JV6T3AKDQP7UY5J7 -j KUBE-SEP-I6T2TXN3D36S6GQI
- -A KUBE-SVC-NPX46M4PTMTKRN6Y -m statistic --mode random --probability 0.33332999982 -j KUBE-SEP-T5JK32PCSUGR3PRV
- -A KUBE-SVC-NPX46M4PTMTKRN6Y -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-ENBFHXAAZ3V67RLH
- -A KUBE-SVC-NPX46M4PTMTKRN6Y -j KUBE-SEP-UNHMTT7BF3FQAUBW
- -A KUBE-SVC-TCOU7JCQXEZGVUNU -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-E5AJ7SMD4N6IABHF
- -A KUBE-SVC-TCOU7JCQXEZGVUNU -j KUBE-SEP-TV3U67EFPF6RYKGW
- -A KUBE-SVC-U7X4VZNLLMJVC6JR -m statistic --mode random --probability 0.16667000018 -j KUBE-SEP-AXYSTSVUFD26FOJT
- -A KUBE-SVC-U7X4VZNLLMJVC6JR -m statistic --mode random --probability 0.20000000019 -j KUBE-SEP-L7UULNY5HKKVVJNM
- -A KUBE-SVC-U7X4VZNLLMJVC6JR -m statistic --mode random --probability 0.25000000000 -j KUBE-SEP-LAHH7QPLEAC4IYW6
- -A KUBE-SVC-U7X4VZNLLMJVC6JR -m statistic --mode random --probability 0.33332999982 -j KUBE-SEP-RQQBQZBLXJLIS4XR
- -A KUBE-SVC-U7X4VZNLLMJVC6JR -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-422ARSXEMT65DMO3
- -A KUBE-SVC-U7X4VZNLLMJVC6JR -j KUBE-SEP-2HA5TZC4IRJHZTCK
- COMMIT
- # Completed on Fri Jan 15 17:31:19 2021
- # Generated by iptables-save v1.6.0 on Fri Jan 15 17:31:19 2021
- *filter
- :INPUT ACCEPT [729:93366]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [704:116687]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- :KUBE-EXTERNAL-SERVICES - [0:0]
- :KUBE-FIREWALL - [0:0]
- :KUBE-FORWARD - [0:0]
- :KUBE-SERVICES - [0:0]
- -A INPUT -d 169.254.20.10/32 -p udp -m udp --dport 53 -j ACCEPT
- -A INPUT -d 169.254.20.10/32 -p tcp -m tcp --dport 53 -j ACCEPT
- -A INPUT -m conntrack --ctstate NEW -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A INPUT -m conntrack --ctstate NEW -m comment --comment "kubernetes externally-visible service portals" -j KUBE-EXTERNAL-SERVICES
- -A INPUT -j KUBE-FIREWALL
- -A FORWARD -m comment --comment "kubernetes forwarding rules" -j KUBE-FORWARD
- -A FORWARD -m conntrack --ctstate NEW -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-ISOLATION-STAGE-1
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A FORWARD -p tcp -j ACCEPT
- -A FORWARD -p udp -j ACCEPT
- -A FORWARD -p icmp -j ACCEPT
- -A OUTPUT -s 169.254.20.10/32 -p udp -m udp --sport 53 -j ACCEPT
- -A OUTPUT -s 169.254.20.10/32 -p tcp -m tcp --sport 53 -j ACCEPT
- -A OUTPUT -m conntrack --ctstate NEW -m comment --comment "kubernetes service portals" -j KUBE-SERVICES
- -A OUTPUT -j KUBE-FIREWALL
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -j RETURN
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -j RETURN
- -A DOCKER-USER -j RETURN
- -A KUBE-FIREWALL -m comment --comment "kubernetes firewall for dropping marked packets" -m mark --mark 0x8000/0x8000 -j DROP
- -A KUBE-FORWARD -m conntrack --ctstate INVALID -j DROP
- -A KUBE-FORWARD -m comment --comment "kubernetes forwarding rules" -m mark --mark 0x4000/0x4000 -j ACCEPT
- -A KUBE-FORWARD -s 100.96.0.0/11 -m comment --comment "kubernetes forwarding conntrack pod source rule" -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A KUBE-FORWARD -d 100.96.0.0/11 -m comment --comment "kubernetes forwarding conntrack pod destination rule" -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A KUBE-SERVICES -d 100.69.245.97/32 -p tcp -m comment --comment "monitoring/grafana:http has no endpoints" -m tcp --dport 3000 -j REJECT --reject-with icmp-port-unreachable
- COMMIT
- # Completed on Fri Jan 15 17:31:19 2021
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement