|
| 1 | +# Generated by iptables-save v1.6.0 on Mon Sep 14 11:19:43 2020 |
| 2 | +*nat |
| 3 | +:PREROUTING ACCEPT [0:0] |
| 4 | +:INPUT ACCEPT [0:0] |
| 5 | +:OUTPUT ACCEPT [0:0] |
| 6 | +:POSTROUTING ACCEPT [0:0] |
| 7 | +:DOCKER - [0:0] |
| 8 | +-A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER |
| 9 | +-A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER |
| 10 | +-A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE |
| 11 | +-A DOCKER -i docker0 -j RETURN |
| 12 | +COMMIT |
| 13 | +# Completed on Mon Sep 14 11:19:43 2020 |
| 14 | +# Generated by iptables-save v1.6.0 on Mon Sep 14 11:19:43 2020 |
| 15 | +*filter |
| 16 | +:INPUT ACCEPT [2:104] |
| 17 | +:FORWARD DROP [0:0] |
| 18 | +:OUTPUT ACCEPT [49:13320] |
| 19 | +:DOCKER - [0:0] |
| 20 | +:DOCKER-ISOLATION-STAGE-1 - [0:0] |
| 21 | +:DOCKER-ISOLATION-STAGE-2 - [0:0] |
| 22 | +:DOCKER-USER - [0:0] |
| 23 | +-A INPUT -i lo -j ACCEPT |
| 24 | +-A INPUT -d 127.0.0.0/8 ! -i lo -j REJECT --reject-with icmp-port-unreachable |
| 25 | +{% for dict_item in PF_TABLES.target_network_ranges %} |
| 26 | +-A INPUT -s {{dict_item}} -d {{ipv4}}/32 -j REJECT --reject-with icmp-port-unreachable |
| 27 | +{% endfor %} |
| 28 | +-A FORWARD -j DOCKER-USER |
| 29 | +-A FORWARD -j DOCKER-ISOLATION-STAGE-1 |
| 30 | +-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT |
| 31 | +-A FORWARD -o docker0 -j DOCKER |
| 32 | +-A FORWARD -i docker0 ! -o docker0 -j ACCEPT |
| 33 | +-A FORWARD -i docker0 -o docker0 -j ACCEPT |
| 34 | +-A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2 |
| 35 | +-A DOCKER-ISOLATION-STAGE-1 -j RETURN |
| 36 | +-A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP |
| 37 | +-A DOCKER-ISOLATION-STAGE-2 -j RETURN |
| 38 | +-A DOCKER-USER -j RETURN |
| 39 | +COMMIT |
| 40 | +# Completed on Mon Sep 14 11:19:43 2020 |
0 commit comments