Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.8.10 (nf_tables) on Thu May 1 15:38:56 2025
- *raw
- :PREROUTING ACCEPT [6958:715666]
- :OUTPUT ACCEPT [5865:638041]
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 19132 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 25250 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 2053 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 51821 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 5555 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 52865 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 81 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 443 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.6/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.7/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 3000 -j DROP
- -A PREROUTING -d 172.19.0.8/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8088 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 19132 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 25250 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 2053 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 51821 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 5555 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 52865 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 81 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 443 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.6/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.7/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 3000 -j DROP
- -A PREROUTING -d 172.19.0.8/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8088 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 19132 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 25250 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 2053 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 51821 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 5555 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 52865 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 81 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 443 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.6/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.7/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 3000 -j DROP
- -A PREROUTING -d 172.19.0.8/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8088 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 19132 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p udp -m udp --dport 25250 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 2053 -j DROP
- -A PREROUTING -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 51821 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 5555 -j DROP
- -A PREROUTING -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 52865 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 81 -j DROP
- -A PREROUTING -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 443 -j DROP
- -A PREROUTING -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DROP
- -A PREROUTING -d 172.19.0.6/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- -A PREROUTING -d 172.19.0.7/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 3000 -j DROP
- -A PREROUTING -d 172.19.0.8/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8088 -j DROP
- -A PREROUTING -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DROP
- COMMIT
- # Completed on Thu May 1 15:38:56 2025
- # Generated by iptables-save v1.8.10 (nf_tables) on Thu May 1 15:38:56 2025
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [5864:637965]
- :DOCKER - [0:0]
- :DOCKER-BRIDGE - [0:0]
- :DOCKER-CT - [0:0]
- :DOCKER-FORWARD - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- :InstanceServices - [0:0]
- :ufw-after-forward - [0:0]
- :ufw-after-input - [0:0]
- :ufw-after-logging-forward - [0:0]
- :ufw-after-logging-input - [0:0]
- :ufw-after-logging-output - [0:0]
- :ufw-after-output - [0:0]
- :ufw-before-forward - [0:0]
- :ufw-before-input - [0:0]
- :ufw-before-logging-forward - [0:0]
- :ufw-before-logging-input - [0:0]
- :ufw-before-logging-output - [0:0]
- :ufw-before-output - [0:0]
- :ufw-reject-forward - [0:0]
- :ufw-reject-input - [0:0]
- :ufw-reject-output - [0:0]
- :ufw-track-forward - [0:0]
- :ufw-track-input - [0:0]
- :ufw-track-output - [0:0]
- -A INPUT -j ufw-before-logging-input
- -A INPUT -j ufw-before-input
- -A INPUT -j ufw-after-input
- -A INPUT -j ufw-after-logging-input
- -A INPUT -j ufw-reject-input
- -A INPUT -j ufw-track-input
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p udp -m udp --sport 123 -j ACCEPT
- -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A INPUT -j ufw-before-logging-input
- -A INPUT -j ufw-before-input
- -A INPUT -j ufw-after-input
- -A INPUT -j ufw-after-logging-input
- -A INPUT -j ufw-reject-input
- -A INPUT -j ufw-track-input
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p udp -m udp --sport 123 -j ACCEPT
- -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A INPUT -j ufw-before-logging-input
- -A INPUT -j ufw-before-input
- -A INPUT -j ufw-after-input
- -A INPUT -j ufw-after-logging-input
- -A INPUT -j ufw-reject-input
- -A INPUT -j ufw-track-input
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p udp -m udp --sport 123 -j ACCEPT
- -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A INPUT -j ufw-before-logging-input
- -A INPUT -j ufw-before-input
- -A INPUT -j ufw-after-input
- -A INPUT -j ufw-after-logging-input
- -A INPUT -j ufw-reject-input
- -A INPUT -j ufw-track-input
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p udp -m udp --sport 123 -j ACCEPT
- -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-FORWARD
- -A FORWARD -j ufw-before-logging-forward
- -A FORWARD -j ufw-before-forward
- -A FORWARD -j ufw-after-forward
- -A FORWARD -j ufw-after-logging-forward
- -A FORWARD -j ufw-reject-forward
- -A FORWARD -j ufw-track-forward
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-FORWARD
- -A FORWARD -j ufw-before-logging-forward
- -A FORWARD -j ufw-before-forward
- -A FORWARD -j ufw-after-forward
- -A FORWARD -j ufw-after-logging-forward
- -A FORWARD -j ufw-reject-forward
- -A FORWARD -j ufw-track-forward
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-FORWARD
- -A FORWARD -j ufw-before-logging-forward
- -A FORWARD -j ufw-before-forward
- -A FORWARD -j ufw-after-forward
- -A FORWARD -j ufw-after-logging-forward
- -A FORWARD -j ufw-reject-forward
- -A FORWARD -j ufw-track-forward
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-FORWARD
- -A FORWARD -j ufw-before-logging-forward
- -A FORWARD -j ufw-before-forward
- -A FORWARD -j ufw-after-forward
- -A FORWARD -j ufw-after-logging-forward
- -A FORWARD -j ufw-reject-forward
- -A FORWARD -j ufw-track-forward
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A OUTPUT -j ufw-before-logging-output
- -A OUTPUT -j ufw-before-output
- -A OUTPUT -j ufw-after-output
- -A OUTPUT -j ufw-after-logging-output
- -A OUTPUT -j ufw-reject-output
- -A OUTPUT -j ufw-track-output
- -A OUTPUT -d 169.254.0.0/16 -j InstanceServices
- -A OUTPUT -j ufw-before-logging-output
- -A OUTPUT -j ufw-before-output
- -A OUTPUT -j ufw-after-output
- -A OUTPUT -j ufw-after-logging-output
- -A OUTPUT -j ufw-reject-output
- -A OUTPUT -j ufw-track-output
- -A OUTPUT -d 169.254.0.0/16 -j InstanceServices
- -A OUTPUT -j ufw-before-logging-output
- -A OUTPUT -j ufw-before-output
- -A OUTPUT -j ufw-after-output
- -A OUTPUT -j ufw-after-logging-output
- -A OUTPUT -j ufw-reject-output
- -A OUTPUT -j ufw-track-output
- -A OUTPUT -d 169.254.0.0/16 -j InstanceServices
- -A OUTPUT -j ufw-before-logging-output
- -A OUTPUT -j ufw-before-output
- -A OUTPUT -j ufw-after-output
- -A OUTPUT -j ufw-after-logging-output
- -A OUTPUT -j ufw-reject-output
- -A OUTPUT -j ufw-track-output
- -A OUTPUT -d 169.254.0.0/16 -j InstanceServices
- -A DOCKER -d 172.19.0.9/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j ACCEPT
- -A DOCKER -d 172.19.0.8/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 8088 -j ACCEPT
- -A DOCKER -d 172.19.0.7/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 3000 -j ACCEPT
- -A DOCKER -d 172.19.0.6/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j ACCEPT
- -A DOCKER -d 172.19.0.5/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j ACCEPT
- -A DOCKER -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 443 -j ACCEPT
- -A DOCKER -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 52865 -j ACCEPT
- -A DOCKER -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 81 -j ACCEPT
- -A DOCKER -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 5555 -j ACCEPT
- -A DOCKER -d 172.19.0.4/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j ACCEPT
- -A DOCKER -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 51821 -j ACCEPT
- -A DOCKER -d 172.19.0.3/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p tcp -m tcp --dport 2053 -j ACCEPT
- -A DOCKER -d 172.19.0.2/32 ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -p udp -m udp --dport 25250 -j ACCEPT
- -A DOCKER ! -i br-54f7df3e5c5b -o br-54f7df3e5c5b -j DROP
- -A DOCKER ! -i docker0 -o docker0 -j DROP
- -A DOCKER-BRIDGE -o br-54f7df3e5c5b -j DOCKER
- -A DOCKER-BRIDGE -o docker0 -j DOCKER
- -A DOCKER-CT -o br-54f7df3e5c5b -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A DOCKER-CT -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A DOCKER-FORWARD -j DOCKER-CT
- -A DOCKER-FORWARD -j DOCKER-ISOLATION-STAGE-1
- -A DOCKER-FORWARD -j DOCKER-BRIDGE
- -A DOCKER-FORWARD -i br-54f7df3e5c5b -j ACCEPT
- -A DOCKER-FORWARD -i docker0 -j ACCEPT
- -A DOCKER-ISOLATION-STAGE-1 -i br-54f7df3e5c5b ! -o br-54f7df3e5c5b -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o br-54f7df3e5c5b -j DROP
- -A DOCKER-USER -j RETURN
- -A InstanceServices -d 169.254.0.2/32 -p tcp -m owner --uid-owner 0 -m tcp --dport 3260 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.2.0/24 -p tcp -m owner --uid-owner 0 -m tcp --dport 3260 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.4.0/24 -p tcp -m owner --uid-owner 0 -m tcp --dport 3260 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.5.0/24 -p tcp -m owner --uid-owner 0 -m tcp --dport 3260 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.0.2/32 -p tcp -m tcp --dport 80 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.169.254/32 -p udp -m udp --dport 53 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.169.254/32 -p tcp -m tcp --dport 53 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.0.3/32 -p tcp -m owner --uid-owner 0 -m tcp --dport 80 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.0.4/32 -p tcp -m tcp --dport 80 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.169.254/32 -p tcp -m tcp --dport 80 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.169.254/32 -p udp -m udp --dport 67 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.169.254/32 -p udp -m udp --dport 69 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.169.254/32 -p udp -m udp --dport 123 -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j ACCEPT
- -A InstanceServices -d 169.254.0.0/16 -p tcp -m tcp -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j REJECT --reject-with tcp-reset
- -A InstanceServices -d 169.254.0.0/16 -p udp -m udp -m comment --comment "See the Oracle-Provided Images section in the Oracle Cloud Infrastructure documentation for security impact of modifying or removing this rule" -j REJECT --reject-with icmp-port-unreachable
- COMMIT
- # Completed on Thu May 1 15:38:56 2025
- # Generated by iptables-save v1.8.10 (nf_tables) on Thu May 1 15:38:56 2025
- *nat
- :PREROUTING ACCEPT [19:1256]
- :INPUT ACCEPT [19:1256]
- :OUTPUT ACCEPT [65:5008]
- :POSTROUTING ACCEPT [0:0]
- :DOCKER - [0:0]
- -A PREROUTING -p udp -m udp --dport 19132 -j DNAT --to-destination 100.64.0.5:19132
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -s 172.19.0.0/16 ! -o br-54f7df3e5c5b -j MASQUERADE
- -A POSTROUTING -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A DOCKER -i br-54f7df3e5c5b -j RETURN
- -A DOCKER ! -i br-54f7df3e5c5b -p udp -m udp --dport 25250 -j DNAT --to-destination 172.19.0.2:25250
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 2053 -j DNAT --to-destination 172.19.0.3:2053
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 51821 -j DNAT --to-destination 172.19.0.2:51821
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.19.0.4:80
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 5555 -j DNAT --to-destination 172.19.0.3:5555
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 81 -j DNAT --to-destination 172.19.0.4:81
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 52865 -j DNAT --to-destination 172.19.0.3:52865
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 443 -j DNAT --to-destination 172.19.0.4:443
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8081 -j DNAT --to-destination 172.19.0.5:80
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8080 -j DNAT --to-destination 172.19.0.6:8080
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 3000 -j DNAT --to-destination 172.19.0.7:3000
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 8088 -j DNAT --to-destination 172.19.0.8:8088
- -A DOCKER ! -i br-54f7df3e5c5b -p tcp -m tcp --dport 2223 -j DNAT --to-destination 172.19.0.9:8080
- COMMIT
- # Completed on Thu May 1 15:38:56 2025
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement