table ip nat { chain DOCKER { } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 2 bytes 1160 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip daddr != 127.0.0.0/8 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain POSTROUTING { type nat hook postrouting priority srcnat; policy accept; ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 0 bytes 0 xt target "MASQUERADE" } } table ip filter { chain DOCKER { iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop } chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE iifname "docker0" counter packets 0 bytes 0 accept } chain DOCKER-BRIDGE { oifname "docker0" counter packets 0 bytes 0 jump DOCKER } chain DOCKER-CT { oifname "docker0" xt match "conntrack" counter packets 0 bytes 0 accept } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy drop; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD counter packets 0 bytes 0 jump ufw-before-logging-forward counter packets 0 bytes 0 jump ufw-before-forward counter packets 0 bytes 0 jump ufw-after-forward counter packets 0 bytes 0 jump ufw-after-logging-forward counter packets 0 bytes 0 jump ufw-reject-forward counter packets 0 bytes 0 jump ufw-track-forward } chain DOCKER-USER { } chain ufw-before-logging-input { } chain ufw-before-logging-output { } chain ufw-before-logging-forward { } chain ufw-before-input { iifname "lo" counter packets 0 bytes 0 accept xt match "conntrack" counter packets 0 bytes 0 accept xt match "conntrack" counter packets 0 bytes 0 jump ufw-logging-deny xt match "conntrack" counter packets 0 bytes 0 drop ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept udp sport 67 udp dport 68 counter packets 0 bytes 0 accept counter packets 0 bytes 0 jump ufw-not-local ip daddr 224.0.0.251 udp dport 5353 counter packets 0 bytes 0 accept ip daddr 239.255.255.250 udp dport 1900 counter packets 0 bytes 0 accept counter packets 0 bytes 0 jump ufw-user-input } chain ufw-before-output { oifname "lo" counter packets 0 bytes 0 accept xt match "conntrack" counter packets 0 bytes 0 accept counter packets 0 bytes 0 jump ufw-user-output } chain ufw-before-forward { xt match "conntrack" counter packets 0 bytes 0 accept ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept counter packets 0 bytes 0 jump ufw-user-forward } chain ufw-after-input { udp dport 137 counter packets 0 bytes 0 jump ufw-skip-to-policy-input udp dport 138 counter packets 0 bytes 0 jump ufw-skip-to-policy-input tcp dport 139 counter packets 0 bytes 0 jump ufw-skip-to-policy-input tcp dport 445 counter packets 0 bytes 0 jump ufw-skip-to-policy-input udp dport 67 counter packets 0 bytes 0 jump ufw-skip-to-policy-input udp dport 68 counter packets 0 bytes 0 jump ufw-skip-to-policy-input xt match "addrtype" counter packets 0 bytes 0 jump ufw-skip-to-policy-input } chain ufw-after-output { } chain ufw-after-forward { } chain ufw-after-logging-input { limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw-after-logging-output { } chain ufw-after-logging-forward { limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw-reject-input { } chain ufw-reject-output { } chain ufw-reject-forward { } chain ufw-track-input { } chain ufw-track-output { ip protocol tcp xt match "conntrack" counter packets 0 bytes 0 accept ip protocol udp xt match "conntrack" counter packets 0 bytes 0 accept } chain ufw-track-forward { } chain INPUT { type filter hook input priority filter; policy drop; counter packets 1 bytes 76 jump ufw-before-logging-input counter packets 1 bytes 76 jump ufw-before-input counter packets 0 bytes 0 jump ufw-after-input counter packets 0 bytes 0 jump ufw-after-logging-input counter packets 0 bytes 0 jump ufw-reject-input counter packets 0 bytes 0 jump ufw-track-input } chain OUTPUT { type filter hook output priority filter; policy accept; counter packets 1 bytes 76 jump ufw-before-logging-output counter packets 1 bytes 76 jump ufw-before-output counter packets 1 bytes 76 jump ufw-after-output counter packets 1 bytes 76 jump ufw-after-logging-output counter packets 1 bytes 76 jump ufw-reject-output counter packets 1 bytes 76 jump ufw-track-output } chain ufw-logging-deny { xt match "conntrack" limit rate 3/minute burst 10 packets counter packets 0 bytes 0 return limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw-logging-allow { limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw-skip-to-policy-input { counter packets 0 bytes 0 drop } chain ufw-skip-to-policy-output { counter packets 0 bytes 0 accept } chain ufw-skip-to-policy-forward { counter packets 0 bytes 0 drop } chain ufw-not-local { xt match "addrtype" counter packets 0 bytes 0 return xt match "addrtype" counter packets 0 bytes 0 return xt match "addrtype" counter packets 0 bytes 0 return limit rate 3/minute burst 10 packets counter packets 0 bytes 0 jump ufw-logging-deny counter packets 0 bytes 0 drop } chain ufw-user-input { tcp dport 22 counter packets 0 bytes 0 accept tcp dport 8080 counter packets 0 bytes 0 accept udp dport 51820 counter packets 0 bytes 0 accept } chain ufw-user-output { } chain ufw-user-forward { tcp dport 80 counter packets 0 bytes 0 accept iifname "mesh0" tcp dport 443 counter packets 0 bytes 0 accept } chain ufw-user-logging-input { } chain ufw-user-logging-output { } chain ufw-user-logging-forward { } chain ufw-user-limit { limit rate 3/minute burst 5 packets counter packets 0 bytes 0 xt target "LOG" counter packets 0 bytes 0 xt target "REJECT" } chain ufw-user-limit-accept { counter packets 0 bytes 0 accept } } table ip6 nat { chain DOCKER { } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip6 daddr != ::1 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } } table ip6 filter { chain DOCKER { } chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE } chain DOCKER-BRIDGE { } chain DOCKER-CT { } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy drop; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD counter packets 0 bytes 0 jump ufw6-before-logging-forward counter packets 0 bytes 0 jump ufw6-before-forward counter packets 0 bytes 0 jump ufw6-after-forward counter packets 0 bytes 0 jump ufw6-after-logging-forward counter packets 0 bytes 0 jump ufw6-reject-forward counter packets 0 bytes 0 jump ufw6-track-forward } chain DOCKER-USER { } chain ufw6-before-logging-input { } chain ufw6-before-logging-output { } chain ufw6-before-logging-forward { } chain ufw6-before-input { iifname "lo" counter packets 0 bytes 0 accept xt match "rt" counter packets 0 bytes 0 drop xt match "conntrack" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept xt match "conntrack" counter packets 0 bytes 0 jump ufw6-logging-deny xt match "conntrack" counter packets 0 bytes 0 drop meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 ip6 daddr fe80::/10 udp sport 547 udp dport 546 counter packets 0 bytes 0 accept ip6 daddr ff02::fb udp dport 5353 counter packets 0 bytes 0 accept ip6 daddr ff02::f udp dport 1900 counter packets 0 bytes 0 accept counter packets 0 bytes 0 jump ufw6-user-input } chain ufw6-before-output { oifname "lo" counter packets 0 bytes 0 accept xt match "rt" counter packets 0 bytes 0 drop xt match "conntrack" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept counter packets 0 bytes 0 jump ufw6-user-output } chain ufw6-before-forward { xt match "rt" counter packets 0 bytes 0 drop xt match "conntrack" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept counter packets 0 bytes 0 jump ufw6-user-forward } chain ufw6-after-input { udp dport 137 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input udp dport 138 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input tcp dport 139 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input tcp dport 445 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input udp dport 546 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input udp dport 547 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input } chain ufw6-after-output { } chain ufw6-after-forward { } chain ufw6-after-logging-input { limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw6-after-logging-output { } chain ufw6-after-logging-forward { limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw6-reject-input { } chain ufw6-reject-output { } chain ufw6-reject-forward { } chain ufw6-track-input { } chain ufw6-track-output { meta l4proto tcp xt match "conntrack" counter packets 0 bytes 0 accept meta l4proto udp xt match "conntrack" counter packets 0 bytes 0 accept } chain ufw6-track-forward { } chain INPUT { type filter hook input priority filter; policy drop; counter packets 1 bytes 128 jump ufw6-before-logging-input counter packets 1 bytes 128 jump ufw6-before-input counter packets 0 bytes 0 jump ufw6-after-input counter packets 0 bytes 0 jump ufw6-after-logging-input counter packets 0 bytes 0 jump ufw6-reject-input counter packets 0 bytes 0 jump ufw6-track-input } chain OUTPUT { type filter hook output priority filter; policy accept; counter packets 4 bytes 304 jump ufw6-before-logging-output counter packets 4 bytes 304 jump ufw6-before-output counter packets 0 bytes 0 jump ufw6-after-output counter packets 0 bytes 0 jump ufw6-after-logging-output counter packets 0 bytes 0 jump ufw6-reject-output counter packets 0 bytes 0 jump ufw6-track-output } chain ufw6-logging-deny { xt match "conntrack" limit rate 3/minute burst 10 packets counter packets 0 bytes 0 return limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw6-logging-allow { limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG" } chain ufw6-skip-to-policy-input { counter packets 0 bytes 0 drop } chain ufw6-skip-to-policy-output { counter packets 0 bytes 0 accept } chain ufw6-skip-to-policy-forward { counter packets 0 bytes 0 drop } chain ufw6-user-input { tcp dport 22 counter packets 0 bytes 0 accept tcp dport 8080 counter packets 0 bytes 0 accept udp dport 51820 counter packets 0 bytes 0 accept } chain ufw6-user-output { } chain ufw6-user-forward { tcp dport 80 counter packets 0 bytes 0 accept iifname "mesh0" tcp dport 443 counter packets 0 bytes 0 accept } chain ufw6-user-logging-input { } chain ufw6-user-logging-output { } chain ufw6-user-logging-forward { } chain ufw6-user-limit { limit rate 3/minute burst 5 packets counter packets 0 bytes 0 xt target "LOG" counter packets 0 bytes 0 xt target "REJECT" } chain ufw6-user-limit-accept { counter packets 0 bytes 0 accept } }