Skip to content

Instantly share code, notes, and snippets.

@frojnd
Created April 29, 2020 19:11
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save frojnd/144ca599336dede9ce993a4dcbf147d6 to your computer and use it in GitHub Desktop.
Save frojnd/144ca599336dede9ce993a4dcbf147d6 to your computer and use it in GitHub Desktop.
# Generated by iptables-save v1.8.4 on Wed Apr 29 21:11:26 2020
*filter
:INPUT ACCEPT [17750:9299587]
:FORWARD DROP [290:18976]
:OUTPUT ACCEPT [19734:2075193]
:DOCKER - [0:0]
:DOCKER-ISOLATION-STAGE-1 - [0:0]
:DOCKER-ISOLATION-STAGE-2 - [0:0]
:DOCKER-USER - [0:0]
[290:18976] -A FORWARD -j DOCKER-USER
[290:18976] -A FORWARD -j DOCKER-ISOLATION-STAGE-1
[0:0] -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
[0:0] -A FORWARD -o docker0 -j DOCKER
[0:0] -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
[0:0] -A FORWARD -i docker0 -o docker0 -j ACCEPT
[0:0] -A FORWARD -o br-759465290b28 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
[0:0] -A FORWARD -o br-759465290b28 -j DOCKER
[0:0] -A FORWARD -i br-759465290b28 ! -o br-759465290b28 -j ACCEPT
[0:0] -A FORWARD -i br-759465290b28 -o br-759465290b28 -j ACCEPT
[0:0] -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
[0:0] -A DOCKER-ISOLATION-STAGE-1 -i br-759465290b28 ! -o br-759465290b28 -j DOCKER-ISOLATION-STAGE-2
[290:18976] -A DOCKER-ISOLATION-STAGE-1 -j RETURN
[0:0] -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
[0:0] -A DOCKER-ISOLATION-STAGE-2 -o br-759465290b28 -j DROP
[0:0] -A DOCKER-ISOLATION-STAGE-2 -j RETURN
[290:18976] -A DOCKER-USER -j RETURN
COMMIT
# Completed on Wed Apr 29 21:11:26 2020
# Generated by iptables-save v1.8.4 on Wed Apr 29 21:11:26 2020
*nat
:PREROUTING ACCEPT [797:151258]
:INPUT ACCEPT [503:124014]
:OUTPUT ACCEPT [1078:78360]
:POSTROUTING ACCEPT [1078:78360]
:DOCKER - [0:0]
[45:46773] -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
[0:0] -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
[0:0] -A POSTROUTING -s 100.1.0.0/20 ! -o docker0 -j MASQUERADE
[0:0] -A POSTROUTING -s 100.1.16.0/20 ! -o br-759465290b28 -j MASQUERADE
[0:0] -A POSTROUTING -s 192.168.2.0/24 -o wlp4s0 -j MASQUERADE
[0:0] -A POSTROUTING -s 192.168.2.0/24 -o wlp4s0 -j MASQUERADE
[0:0] -A POSTROUTING -s 192.168.2.15/32 -o wlp4s0 -j MASQUERADE
[0:0] -A DOCKER -i docker0 -j RETURN
[0:0] -A DOCKER -i br-759465290b28 -j RETURN
COMMIT
# Completed on Wed Apr 29 21:11:26 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment