table ip nat { chain DOCKER { } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip daddr != 127.0.0.0/8 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain POSTROUTING { type nat hook postrouting priority srcnat; policy accept; ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 0 bytes 0 xt target "MASQUERADE" } } table ip filter { chain DOCKER { iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop } chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE iifname "docker0" counter packets 0 bytes 0 accept } chain DOCKER-BRIDGE { oifname "docker0" counter packets 0 bytes 0 jump DOCKER } chain DOCKER-CT { oifname "docker0" xt match "conntrack" counter packets 0 bytes 0 accept } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy drop; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD } chain DOCKER-USER { } } table ip6 nat { chain DOCKER { } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip6 daddr != ::1 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } } table ip6 filter { chain DOCKER { } chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE } chain DOCKER-BRIDGE { } chain DOCKER-CT { } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy accept; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD } chain DOCKER-USER { } } table inet f2b-table { set addr-set-sshd { type ipv4_addr flags interval elements = { 192.0.2.55 } } chain f2b-chain { type filter hook input priority filter - 1; policy accept; tcp dport 22 ip saddr @addr-set-sshd reject with icmp port-unreachable } }