Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.21 on Wed Jan 29 18:43:26 2020
- *nat
- :PREROUTING ACCEPT [7184:431209]
- :INPUT ACCEPT [7184:431209]
- :OUTPUT ACCEPT [13863:866384]
- :POSTROUTING ACCEPT [13863:866384]
- :DOCKER - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_ZONES_SOURCE - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_public - [0:0]
- :POST_public_allow - [0:0]
- :POST_public_deny - [0:0]
- :POST_public_log - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT -j OUTPUT_direct
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -j POSTROUTING_direct
- -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- -A POSTROUTING -j POSTROUTING_ZONES
- -A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.4/32 -d 172.17.0.4/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.5/32 -d 172.17.0.5/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.6/32 -d 172.17.0.6/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.7/32 -d 172.17.0.7/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.8/32 -d 172.17.0.8/32 -p tcp -m tcp --dport 80 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.9/32 -d 172.17.0.9/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.10/32 -d 172.17.0.10/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.11/32 -d 172.17.0.11/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.12/32 -d 172.17.0.12/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.13/32 -d 172.17.0.13/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.14/32 -d 172.17.0.14/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.15/32 -d 172.17.0.15/32 -p tcp -m tcp --dport 80 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.16/32 -d 172.17.0.16/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.17/32 -d 172.17.0.17/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -s 172.17.0.18/32 -d 172.17.0.18/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
- -A POSTROUTING -o wlan0 -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9018 -j DNAT --to-destination 172.17.0.2:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9004 -j DNAT --to-destination 172.17.0.3:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9010 -j DNAT --to-destination 172.17.0.4:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9007 -j DNAT --to-destination 172.17.0.5:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9029 -j DNAT --to-destination 172.17.0.6:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9021 -j DNAT --to-destination 172.17.0.7:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 8092 -j DNAT --to-destination 172.17.0.8:80
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9020 -j DNAT --to-destination 172.17.0.9:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9001 -j DNAT --to-destination 172.17.0.10:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9033 -j DNAT --to-destination 172.17.0.11:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9015 -j DNAT --to-destination 172.17.0.12:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9025 -j DNAT --to-destination 172.17.0.13:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9035 -j DNAT --to-destination 172.17.0.14:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9031 -j DNAT --to-destination 172.17.0.15:80
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9027 -j DNAT --to-destination 172.17.0.16:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9013 -j DNAT --to-destination 172.17.0.17:9000
- -A DOCKER ! -i docker0 -p tcp -m tcp --dport 9023 -j DNAT --to-destination 172.17.0.18:9000
- -A POSTROUTING_ZONES -g POST_public
- -A POST_public -j POST_public_log
- -A POST_public -j POST_public_deny
- -A POST_public -j POST_public_allow
- -A PREROUTING_ZONES -g PRE_public
- -A PRE_public -j PRE_public_log
- -A PRE_public -j PRE_public_deny
- -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Wed Jan 29 18:43:26 2020
- # Generated by iptables-save v1.4.21 on Wed Jan 29 18:43:26 2020
- *mangle
- :PREROUTING ACCEPT [3020363:336231257]
- :INPUT ACCEPT [3012892:335602595]
- :FORWARD ACCEPT [5484:457594]
- :OUTPUT ACCEPT [3342252:635058235]
- :POSTROUTING ACCEPT [3347842:635521006]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- -A POSTROUTING -j POSTROUTING_direct
- -A PREROUTING_ZONES -g PRE_public
- -A PRE_public -j PRE_public_log
- -A PRE_public -j PRE_public_deny
- -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Wed Jan 29 18:43:26 2020
- # Generated by iptables-save v1.4.21 on Wed Jan 29 18:43:26 2020
- *security
- :INPUT ACCEPT [3012627:335588239]
- :FORWARD ACCEPT [5484:457594]
- :OUTPUT ACCEPT [3342252:635058235]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Wed Jan 29 18:43:26 2020
- # Generated by iptables-save v1.4.21 on Wed Jan 29 18:43:26 2020
- *raw
- :PREROUTING ACCEPT [3020363:336231257]
- :OUTPUT ACCEPT [3342252:635058235]
- :OUTPUT_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A OUTPUT -j OUTPUT_direct
- -A PREROUTING_ZONES -g PRE_public
- -A PRE_public -j PRE_public_log
- -A PRE_public -j PRE_public_deny
- -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Wed Jan 29 18:43:26 2020
- # Generated by iptables-save v1.4.21 on Wed Jan 29 18:43:26 2020
- *filter
- :INPUT ACCEPT [103710:9345819]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [114829:18909338]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_IN_ZONES_SOURCE - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_OUT_ZONES_SOURCE - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_public - [0:0]
- :FWDI_public_allow - [0:0]
- :FWDI_public_deny - [0:0]
- :FWDI_public_log - [0:0]
- :FWDO_public - [0:0]
- :FWDO_public_allow - [0:0]
- :FWDO_public_deny - [0:0]
- :FWDO_public_log - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_ZONES_SOURCE - [0:0]
- :INPUT_direct - [0:0]
- :IN_public - [0:0]
- :IN_public_allow - [0:0]
- :IN_public_deny - [0:0]
- :IN_public_log - [0:0]
- :OUTPUT_direct - [0:0]
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-ISOLATION-STAGE-1
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A FORWARD -i wlan1 -o wlan0 -j ACCEPT
- -A FORWARD -i wlan0 -o wlan1 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i veth4121ad8 -o eth0 -j ACCEPT
- -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.4/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.5/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.7/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.8/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A DOCKER -d 172.17.0.9/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.10/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.11/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.12/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.13/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.14/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.15/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A DOCKER -d 172.17.0.16/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.17/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER -d 172.17.0.18/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -j RETURN
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -j RETURN
- -A DOCKER-USER -j RETURN
- COMMIT
- # Completed on Wed Jan 29 18:43:26 2020
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement