Skip to content

Instantly share code, notes, and snippets.

@khanghh
Created July 16, 2019 06:08
Show Gist options
  • Save khanghh/3ab128d8bb45e6eb5bc13abbc6645907 to your computer and use it in GitHub Desktop.
Save khanghh/3ab128d8bb45e6eb5bc13abbc6645907 to your computer and use it in GitHub Desktop.
/etc/iptables.sav
# Generated by iptables-save v1.6.1 on Mon Mar 18 09:14:22 2019
*nat
:PREROUTING ACCEPT [35:2266]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [119:8876]
:POSTROUTING ACCEPT [119:8876]
:DOCKER - [0:0]
-A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
-A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
-A POSTROUTING -s 192.168.56.0/24 -j MASQUERADE
-A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
-A POSTROUTING -s 172.22.0.0/16 ! -o br-bcf9ed835f61 -j MASQUERADE
-A POSTROUTING -s 172.21.0.0/16 ! -o br-5cd44351130a -j MASQUERADE
-A POSTROUTING -s 172.20.0.0/16 ! -o br-5c7db701ccd8 -j MASQUERADE
-A POSTROUTING -s 172.19.0.0/16 ! -o br-5021d57326b6 -j MASQUERADE
-A POSTROUTING -s 172.18.0.0/16 ! -o br-27801ef4e589 -j MASQUERADE
-A DOCKER -i docker0 -j RETURN
-A DOCKER -i br-bcf9ed835f61 -j RETURN
-A DOCKER -i br-5cd44351130a -j RETURN
-A DOCKER -i br-5c7db701ccd8 -j RETURN
-A DOCKER -i br-5021d57326b6 -j RETURN
-A DOCKER -i br-27801ef4e589 -j RETURN
COMMIT
# Completed on Mon Mar 18 09:14:22 2019
# Generated by iptables-save v1.6.1 on Mon Mar 18 09:14:22 2019
*mangle
:PREROUTING ACCEPT [763:151028]
:INPUT ACCEPT [387:70821]
:FORWARD ACCEPT [376:80207]
:OUTPUT ACCEPT [426:34168]
:POSTROUTING ACCEPT [815:117614]
COMMIT
# Completed on Mon Mar 18 09:14:22 2019
# Generated by iptables-save v1.6.1 on Mon Mar 18 09:14:22 2019
*filter
:INPUT ACCEPT [347:68634]
:FORWARD ACCEPT [343:78222]
:OUTPUT ACCEPT [386:31521]
:DOCKER - [0:0]
:DOCKER-ISOLATION-STAGE-1 - [0:0]
:DOCKER-ISOLATION-STAGE-2 - [0:0]
:DOCKER-USER - [0:0]
-A FORWARD -j DOCKER-USER
-A FORWARD -j DOCKER-ISOLATION-STAGE-1
-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o docker0 -j DOCKER
-A FORWARD -i docker0 ! -o docker0 -j ACCEPT
-A FORWARD -i docker0 -o docker0 -j ACCEPT
-A FORWARD -o br-bcf9ed835f61 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-bcf9ed835f61 -j DOCKER
-A FORWARD -i br-bcf9ed835f61 ! -o br-bcf9ed835f61 -j ACCEPT
-A FORWARD -i br-bcf9ed835f61 -o br-bcf9ed835f61 -j ACCEPT
-A FORWARD -o br-5cd44351130a -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-5cd44351130a -j DOCKER
-A FORWARD -i br-5cd44351130a ! -o br-5cd44351130a -j ACCEPT
-A FORWARD -i br-5cd44351130a -o br-5cd44351130a -j ACCEPT
-A FORWARD -o br-5c7db701ccd8 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-5c7db701ccd8 -j DOCKER
-A FORWARD -i br-5c7db701ccd8 ! -o br-5c7db701ccd8 -j ACCEPT
-A FORWARD -i br-5c7db701ccd8 -o br-5c7db701ccd8 -j ACCEPT
-A FORWARD -o br-5021d57326b6 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-5021d57326b6 -j DOCKER
-A FORWARD -i br-5021d57326b6 ! -o br-5021d57326b6 -j ACCEPT
-A FORWARD -i br-5021d57326b6 -o br-5021d57326b6 -j ACCEPT
-A FORWARD -o br-27801ef4e589 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-27801ef4e589 -j DOCKER
-A FORWARD -i br-27801ef4e589 ! -o br-27801ef4e589 -j ACCEPT
-A FORWARD -i br-27801ef4e589 -o br-27801ef4e589 -j ACCEPT
-A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i br-bcf9ed835f61 ! -o br-bcf9ed835f61 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i br-5cd44351130a ! -o br-5cd44351130a -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i br-5c7db701ccd8 ! -o br-5c7db701ccd8 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i br-5021d57326b6 ! -o br-5021d57326b6 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i br-27801ef4e589 ! -o br-27801ef4e589 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -j RETURN
-A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o br-bcf9ed835f61 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o br-5cd44351130a -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o br-5c7db701ccd8 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o br-5021d57326b6 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o br-27801ef4e589 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -j RETURN
-A DOCKER-USER -j RETURN
COMMIT
# Completed on Mon Mar 18 09:14:22 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment