# Warning: table ip nat is managed by iptables-nft, do not touch! table ip nat { chain DOCKER { iifname != "br-8df157c45a69" tcp dport 8112 counter packets 62 bytes 3224 dnat to 172.18.0.7:8787 iifname != "br-8df157c45a69" tcp dport 8109 counter packets 160 bytes 8309 dnat to 172.18.0.8:9696 iifname != "br-8df157c45a69" tcp dport 6767 counter packets 0 bytes 0 dnat to 172.18.0.10:6767 iifname != "br-8df157c45a69" tcp dport 8098 counter packets 253 bytes 14572 dnat to 172.18.0.11:8989 iifname != "br-8df157c45a69" tcp dport 8131 counter packets 0 bytes 0 dnat to 172.18.0.14:8686 iifname != "br-8df157c45a69" tcp dport 8014 counter packets 0 bytes 0 dnat to 172.18.0.15:8014 iifname != "br-8df157c45a69" udp dport 6881 counter packets 5 bytes 492 dnat to 172.18.0.9:6881 iifname != "br-8df157c45a69" tcp dport 8133 counter packets 31 bytes 1612 dnat to 172.18.0.9:8133 iifname != "br-8df157c45a69" tcp dport 5672 counter packets 0 bytes 0 dnat to 172.18.0.3:5672 iifname != "br-8df157c45a69" tcp dport 80 counter packets 43 bytes 2236 dnat to 172.18.0.5:80 iifname != "br-8df157c45a69" tcp dport 443 counter packets 0 bytes 0 dnat to 172.18.0.5:443 } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; fib daddr type local counter packets 42342 bytes 2892885 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip daddr != 127.0.0.0/8 fib daddr type local counter packets 38020 bytes 2488097 jump DOCKER } chain POSTROUTING { type nat hook postrouting priority srcnat; policy accept; ip saddr 10.128.15.0/24 oifname != "br-b442ad6af144" counter packets 0 bytes 0 masquerade ip saddr 10.128.19.0/24 oifname != "br-a4e9cd72923e" counter packets 0 bytes 0 masquerade ip saddr 10.128.14.0/24 oifname != "br-5fe5d8c8806b" counter packets 0 bytes 0 masquerade ip saddr 10.128.11.0/24 oifname != "br-68dbfddf4b8a" counter packets 0 bytes 0 masquerade ip saddr 10.128.12.0/24 oifname != "br-cfe298a09e6f" counter packets 0 bytes 0 masquerade ip saddr 10.128.17.0/24 oifname != "br-fd3b70bb6463" counter packets 0 bytes 0 masquerade ip saddr 10.128.13.0/24 oifname != "br-0a8b22c1e1f5" counter packets 0 bytes 0 masquerade ip saddr 172.18.0.0/16 oifname != "br-8df157c45a69" counter packets 258880 bytes 26232670 masquerade ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 0 bytes 0 masquerade } } # Warning: table ip filter is managed by iptables-nft, do not touch! table ip filter { chain DOCKER { ip daddr 172.18.0.5 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 443 counter packets 0 bytes 0 accept ip daddr 172.18.0.5 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 80 counter packets 43 bytes 2236 accept ip daddr 172.18.0.3 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 5672 counter packets 0 bytes 0 accept ip daddr 172.18.0.9 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 8133 counter packets 31 bytes 1612 accept ip daddr 172.18.0.9 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" udp dport 6881 counter packets 15 bytes 1812 accept ip daddr 172.18.0.15 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 8014 counter packets 0 bytes 0 accept ip daddr 172.18.0.14 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 8686 counter packets 0 bytes 0 accept ip daddr 172.18.0.11 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 8989 counter packets 253 bytes 14572 accept ip daddr 172.18.0.10 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 6767 counter packets 0 bytes 0 accept ip daddr 172.18.0.8 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 9696 counter packets 160 bytes 8309 accept ip daddr 172.18.0.7 iifname != "br-8df157c45a69" oifname "br-8df157c45a69" tcp dport 8787 counter packets 62 bytes 3224 accept iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop iifname != "br-8df157c45a69" oifname "br-8df157c45a69" counter packets 1 bytes 52 drop iifname != "br-0a8b22c1e1f5" oifname "br-0a8b22c1e1f5" counter packets 0 bytes 0 drop iifname != "br-fd3b70bb6463" oifname "br-fd3b70bb6463" counter packets 0 bytes 0 drop iifname != "br-cfe298a09e6f" oifname "br-cfe298a09e6f" counter packets 0 bytes 0 drop iifname != "br-68dbfddf4b8a" oifname "br-68dbfddf4b8a" counter packets 0 bytes 0 drop iifname != "br-5fe5d8c8806b" oifname "br-5fe5d8c8806b" counter packets 0 bytes 0 drop iifname != "br-a4e9cd72923e" oifname "br-a4e9cd72923e" counter packets 0 bytes 0 drop iifname != "br-b442ad6af144" oifname "br-b442ad6af144" counter packets 0 bytes 0 drop } chain DOCKER-FORWARD { counter packets 3916322 bytes 2102949515 jump DOCKER-CT counter packets 2019976 bytes 454801269 jump DOCKER-INTERNAL counter packets 2019976 bytes 454801269 jump DOCKER-BRIDGE iifname "docker0" counter packets 0 bytes 0 accept iifname "br-8df157c45a69" counter packets 1880063 bytes 380976821 accept iifname "br-0a8b22c1e1f5" counter packets 0 bytes 0 accept iifname "br-fd3b70bb6463" counter packets 0 bytes 0 accept iifname "br-cfe298a09e6f" counter packets 0 bytes 0 accept iifname "br-68dbfddf4b8a" counter packets 0 bytes 0 accept iifname "br-5fe5d8c8806b" counter packets 0 bytes 0 accept iifname "br-a4e9cd72923e" counter packets 0 bytes 0 accept iifname "br-b442ad6af144" counter packets 0 bytes 0 accept } chain DOCKER-BRIDGE { oifname "docker0" counter packets 0 bytes 0 jump DOCKER oifname "br-8df157c45a69" counter packets 36172 bytes 2519027 jump DOCKER oifname "br-0a8b22c1e1f5" counter packets 0 bytes 0 jump DOCKER oifname "br-fd3b70bb6463" counter packets 0 bytes 0 jump DOCKER oifname "br-cfe298a09e6f" counter packets 0 bytes 0 jump DOCKER oifname "br-68dbfddf4b8a" counter packets 0 bytes 0 jump DOCKER oifname "br-5fe5d8c8806b" counter packets 0 bytes 0 jump DOCKER oifname "br-a4e9cd72923e" counter packets 0 bytes 0 jump DOCKER oifname "br-b442ad6af144" counter packets 0 bytes 0 jump DOCKER } chain DOCKER-CT { oifname "docker0" ct state related,established counter packets 0 bytes 0 accept oifname "br-8df157c45a69" ct state related,established counter packets 1792726 bytes 1562539426 accept oifname "br-0a8b22c1e1f5" ct state related,established counter packets 0 bytes 0 accept oifname "br-fd3b70bb6463" ct state related,established counter packets 0 bytes 0 accept oifname "br-cfe298a09e6f" ct state related,established counter packets 0 bytes 0 accept oifname "br-68dbfddf4b8a" ct state related,established counter packets 0 bytes 0 accept oifname "br-5fe5d8c8806b" ct state related,established counter packets 0 bytes 0 accept oifname "br-a4e9cd72923e" ct state related,established counter packets 0 bytes 0 accept oifname "br-b442ad6af144" ct state related,established counter packets 0 bytes 0 accept } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy drop; counter packets 3916322 bytes 2102949515 jump DOCKER-USER counter packets 3916322 bytes 2102949515 jump DOCKER-FORWARD } chain DOCKER-USER { } } # Warning: table ip6 nat is managed by iptables-nft, do not touch! table ip6 nat { chain DOCKER { } chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; fib daddr type local counter packets 0 bytes 0 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip6 daddr != ::1 fib daddr type local counter packets 0 bytes 0 jump DOCKER } } table ip6 filter { chain DOCKER { } chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE } chain DOCKER-BRIDGE { } chain DOCKER-CT { } chain DOCKER-INTERNAL { } chain FORWARD { type filter hook forward priority filter; policy accept; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD } chain DOCKER-USER { } } table ip raw { chain PREROUTING { type filter hook prerouting priority raw; policy accept; ip daddr 10.128.13.2 iifname != "br-0a8b22c1e1f5" counter packets 0 bytes 0 drop ip daddr 172.18.0.7 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 172.18.0.8 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 10.128.17.2 iifname != "br-fd3b70bb6463" counter packets 0 bytes 0 drop ip daddr 172.18.0.10 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 10.128.12.2 iifname != "br-cfe298a09e6f" counter packets 0 bytes 0 drop ip daddr 172.18.0.11 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 10.128.11.2 iifname != "br-68dbfddf4b8a" counter packets 0 bytes 0 drop ip daddr 172.18.0.14 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 10.128.14.2 iifname != "br-5fe5d8c8806b" counter packets 0 bytes 0 drop ip daddr 172.18.0.15 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 10.128.19.2 iifname != "br-a4e9cd72923e" counter packets 0 bytes 0 drop ip daddr 10.128.15.2 iifname != "br-b442ad6af144" counter packets 0 bytes 0 drop ip daddr 172.18.0.9 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 172.18.0.2 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 172.18.0.3 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 172.18.0.4 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop ip daddr 172.18.0.5 iifname != "br-8df157c45a69" counter packets 0 bytes 0 drop } }