Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.21 on Thu Jun 20 08:28:50 2019
- *nat
- :PREROUTING ACCEPT [2192683:108413052]
- :INPUT ACCEPT [643832:21257005]
- :OUTPUT ACCEPT [63045:4622106]
- :POSTROUTING ACCEPT [78869:5466248]
- :DOCKER - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_ZONES_SOURCE - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_public - [0:0]
- :POST_public_allow - [0:0]
- :POST_public_deny - [0:0]
- :POST_public_log - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT -j OUTPUT_direct
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -s 172.23.0.0/16 ! -o br-fff74fab8ec0 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.0/16 ! -o br-1cf37af967cc -j MASQUERADE
- -A POSTROUTING -s 172.25.0.0/16 ! -o br-03f8fab54770 -j MASQUERADE
- -A POSTROUTING -j POSTROUTING_direct
- -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- -A POSTROUTING -j POSTROUTING_ZONES
- -A POSTROUTING -s 172.18.0.7/32 -d 172.18.0.7/32 -p tcp -m tcp --dport 443 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.7/32 -d 172.18.0.7/32 -p tcp -m tcp --dport 80 -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A DOCKER -i br-fff74fab8ec0 -j RETURN
- -A DOCKER -i br-1cf37af967cc -j RETURN
- -A DOCKER -i br-03f8fab54770 -j RETURN
- -A DOCKER ! -i br-1cf37af967cc -p tcp -m tcp --dport 443 -j DNAT --to-destination 172.18.0.7:443
- -A DOCKER ! -i br-1cf37af967cc -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.18.0.7:80
- -A POSTROUTING_ZONES -o eth0 -g POST_public
- -A POSTROUTING_ZONES -g POST_public
- -A POST_public -j POST_public_log
- -A POST_public -j POST_public_deny
- -A POST_public -j POST_public_allow
- -A PREROUTING_ZONES -i eth0 -g PRE_public
- -A PREROUTING_ZONES -g PRE_public
- -A PRE_public -j PRE_public_log
- -A PRE_public -j PRE_public_deny
- -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Thu Jun 20 08:28:50 2019
- # Generated by iptables-save v1.4.21 on Thu Jun 20 08:28:50 2019
- *mangle
- :PREROUTING ACCEPT [3257805:833396033]
- :INPUT ACCEPT [2577647:184053966]
- :FORWARD ACCEPT [680158:649342067]
- :OUTPUT ACCEPT [1305542:154372693]
- :POSTROUTING ACCEPT [1985700:803714760]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- -A POSTROUTING -j POSTROUTING_direct
- -A PREROUTING_ZONES -i eth0 -g PRE_public
- -A PREROUTING_ZONES -g PRE_public
- -A PRE_public -j PRE_public_log
- -A PRE_public -j PRE_public_deny
- -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Thu Jun 20 08:28:50 2019
- # Generated by iptables-save v1.4.21 on Thu Jun 20 08:28:50 2019
- *security
- :INPUT ACCEPT [1012027:96118464]
- :FORWARD ACCEPT [680158:649342067]
- :OUTPUT ACCEPT [1305542:154372693]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Thu Jun 20 08:28:50 2019
- # Generated by iptables-save v1.4.21 on Thu Jun 20 08:28:50 2019
- *raw
- :PREROUTING ACCEPT [3257805:833396033]
- :OUTPUT ACCEPT [1305542:154372693]
- :OUTPUT_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A OUTPUT -j OUTPUT_direct
- -A PREROUTING_ZONES -i eth0 -g PRE_public
- -A PREROUTING_ZONES -g PRE_public
- -A PRE_public -j PRE_public_log
- -A PRE_public -j PRE_public_deny
- -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Thu Jun 20 08:28:50 2019
- # Generated by iptables-save v1.4.21 on Thu Jun 20 08:28:50 2019
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [1298574:153648384]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_IN_ZONES_SOURCE - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_OUT_ZONES_SOURCE - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_public - [0:0]
- :FWDI_public_allow - [0:0]
- :FWDI_public_deny - [0:0]
- :FWDI_public_log - [0:0]
- :FWDO_public - [0:0]
- :FWDO_public_allow - [0:0]
- :FWDO_public_deny - [0:0]
- :FWDO_public_log - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_ZONES_SOURCE - [0:0]
- :INPUT_direct - [0:0]
- :IN_public - [0:0]
- :IN_public_allow - [0:0]
- :IN_public_deny - [0:0]
- :IN_public_log - [0:0]
- :OUTPUT_direct - [0:0]
- -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -j INPUT_direct
- -A INPUT -j INPUT_ZONES_SOURCE
- -A INPUT -j INPUT_ZONES
- -A INPUT -m conntrack --ctstate INVALID -j DROP
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-ISOLATION-STAGE-1
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A FORWARD -o br-fff74fab8ec0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o br-fff74fab8ec0 -j DOCKER
- -A FORWARD -i br-fff74fab8ec0 ! -o br-fff74fab8ec0 -j ACCEPT
- -A FORWARD -i br-fff74fab8ec0 -o br-fff74fab8ec0 -j ACCEPT
- -A FORWARD -o br-1cf37af967cc -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o br-1cf37af967cc -j DOCKER
- -A FORWARD -i br-1cf37af967cc ! -o br-1cf37af967cc -j ACCEPT
- -A FORWARD -i br-1cf37af967cc -o br-1cf37af967cc -j ACCEPT
- -A FORWARD -o br-03f8fab54770 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o br-03f8fab54770 -j DOCKER
- -A FORWARD -i br-03f8fab54770 ! -o br-03f8fab54770 -j ACCEPT
- -A FORWARD -i br-03f8fab54770 -o br-03f8fab54770 -j ACCEPT
- -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i lo -j ACCEPT
- -A FORWARD -j FORWARD_direct
- -A FORWARD -j FORWARD_IN_ZONES_SOURCE
- -A FORWARD -j FORWARD_IN_ZONES
- -A FORWARD -j FORWARD_OUT_ZONES_SOURCE
- -A FORWARD -j FORWARD_OUT_ZONES
- -A FORWARD -m conntrack --ctstate INVALID -j DROP
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A OUTPUT -j OUTPUT_direct
- -A DOCKER -d 172.18.0.7/32 ! -i br-1cf37af967cc -o br-1cf37af967cc -p tcp -m tcp --dport 443 -j ACCEPT
- -A DOCKER -d 172.18.0.7/32 ! -i br-1cf37af967cc -o br-1cf37af967cc -p tcp -m tcp --dport 80 -j ACCEPT
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i br-fff74fab8ec0 ! -o br-fff74fab8ec0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i br-1cf37af967cc ! -o br-1cf37af967cc -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i br-03f8fab54770 ! -o br-03f8fab54770 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -j RETURN
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o br-fff74fab8ec0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o br-1cf37af967cc -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o br-03f8fab54770 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -j RETURN
- -A DOCKER-USER -j RETURN
- -A FORWARD_IN_ZONES -i eth0 -g FWDI_public
- -A FORWARD_IN_ZONES -g FWDI_public
- -A FORWARD_OUT_ZONES -o eth0 -g FWDO_public
- -A FORWARD_OUT_ZONES -g FWDO_public
- -A FWDI_public -j FWDI_public_log
- -A FWDI_public -j FWDI_public_deny
- -A FWDI_public -j FWDI_public_allow
- -A FWDI_public -p icmp -j ACCEPT
- -A FWDO_public -j FWDO_public_log
- -A FWDO_public -j FWDO_public_deny
- -A FWDO_public -j FWDO_public_allow
- -A INPUT_ZONES -i eth0 -g IN_public
- -A INPUT_ZONES -g IN_public
- -A IN_public -j IN_public_log
- -A IN_public -j IN_public_deny
- -A IN_public -j IN_public_allow
- -A IN_public -p icmp -j ACCEPT
- -A IN_public_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- COMMIT
- # Completed on Thu Jun 20 08:28:50 2019
Advertisement
Add Comment
Please, Sign In to add comment