table ip nat { chain DOCKER { } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip daddr != 127.0.0.0/8 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain POSTROUTING { type nat hook postrouting priority srcnat; policy accept; ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 0 bytes 0 xt target "MASQUERADE" } } table ip filter { chain DOCKER { iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop } chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE iifname "docker0" counter packets 0 bytes 0 accept } chain DOCKER-BRIDGE { oifname "docker0" counter packets 0 bytes 0 jump DOCKER } chain DOCKER-CT { oifname "docker0" xt match "conntrack" counter packets 0 bytes 0 accept } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy drop; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD } chain DOCKER-USER { } chain f2b-sshd { ip saddr 192.0.2.55 counter packets 0 bytes 0 xt target "REJECT" counter packets 0 bytes 0 return } chain INPUT { type filter hook input priority filter; policy accept; ip protocol tcp xt match "multiport" counter packets 0 bytes 0 jump f2b-sshd } } table ip6 nat { chain DOCKER { } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip6 daddr != ::1 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } } table ip6 filter { chain DOCKER { } chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE } chain DOCKER-BRIDGE { } chain DOCKER-CT { } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy accept; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD } chain DOCKER-USER { } }