- [root@cloud ~]# iptables -L -n
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- INPUT_direct all -- 0.0.0.0/0 0.0.0.0/0
- INPUT_ZONES_SOURCE all -- 0.0.0.0/0 0.0.0.0/0
- INPUT_ZONES all -- 0.0.0.0/0 0.0.0.0/0
- DROP all -- 0.0.0.0/0 0.0.0.0/0 ctstate INVALID
- REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- DOCKER-ISOLATION-STAGE-1 all -- 0.0.0.0/0 0.0.0.0/0
- DOCKER-USER all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- DOCKER all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- FORWARD_direct all -- 0.0.0.0/0 0.0.0.0/0
- FORWARD_IN_ZONES_SOURCE all -- 0.0.0.0/0 0.0.0.0/0
- FORWARD_IN_ZONES all -- 0.0.0.0/0 0.0.0.0/0
- FORWARD_OUT_ZONES_SOURCE all -- 0.0.0.0/0 0.0.0.0/0
- FORWARD_OUT_ZONES all -- 0.0.0.0/0 0.0.0.0/0
- DROP all -- 0.0.0.0/0 0.0.0.0/0 ctstate INVALID
- REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- OUTPUT_direct all -- 0.0.0.0/0 0.0.0.0/0
- Chain DOCKER (1 references)
- target prot opt source destination
- ACCEPT tcp -- 0.0.0.0/0 172.17.0.2 tcp dpt:10000
- Chain DOCKER-ISOLATION-STAGE-1 (1 references)
- target prot opt source destination
- RETURN all -- 0.0.0.0/0 0.0.0.0/0
- Chain DOCKER-ISOLATION-STAGE-2 (0 references)
- target prot opt source destination
- RETURN all -- 0.0.0.0/0 0.0.0.0/0
- Chain DOCKER-USER (1 references)
- target prot opt source destination
- RETURN all -- 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD_IN_ZONES (1 references)
- target prot opt source destination
- FWDI_docker all -- 0.0.0.0/0 0.0.0.0/0 [goto]
- FWDI_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
- Chain FORWARD_IN_ZONES_SOURCE (1 references)
- target prot opt source destination
- Chain FORWARD_OUT_ZONES (1 references)
- target prot opt source destination
- FWDO_docker all -- 0.0.0.0/0 0.0.0.0/0 [goto]
- FWDO_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
- Chain FORWARD_OUT_ZONES_SOURCE (1 references)
- target prot opt source destination
- Chain FORWARD_direct (1 references)
- target prot opt source destination
- Chain FWDI_docker (1 references)
- target prot opt source destination
- FWDI_docker_log all -- 0.0.0.0/0 0.0.0.0/0
- FWDI_docker_deny all -- 0.0.0.0/0 0.0.0.0/0
- FWDI_docker_allow all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- Chain FWDI_docker_allow (1 references)
- target prot opt source destination
- Chain FWDI_docker_deny (1 references)
- target prot opt source destination
- Chain FWDI_docker_log (1 references)
- target prot opt source destination
- Chain FWDI_public (1 references)
- target prot opt source destination
- FWDI_public_log all -- 0.0.0.0/0 0.0.0.0/0
- FWDI_public_deny all -- 0.0.0.0/0 0.0.0.0/0
- FWDI_public_allow all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
- Chain FWDI_public_allow (1 references)
- target prot opt source destination
- Chain FWDI_public_deny (1 references)
- target prot opt source destination
- Chain FWDI_public_log (1 references)
- target prot opt source destination
- Chain FWDO_docker (1 references)
- target prot opt source destination
- FWDO_docker_log all -- 0.0.0.0/0 0.0.0.0/0
- FWDO_docker_deny all -- 0.0.0.0/0 0.0.0.0/0
- FWDO_docker_allow all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- Chain FWDO_docker_allow (1 references)
- target prot opt source destination
- Chain FWDO_docker_deny (1 references)
- target prot opt source destination
- Chain FWDO_docker_log (1 references)
- target prot opt source destination
- Chain FWDO_public (1 references)
- target prot opt source destination
- FWDO_public_log all -- 0.0.0.0/0 0.0.0.0/0
- FWDO_public_deny all -- 0.0.0.0/0 0.0.0.0/0
- FWDO_public_allow all -- 0.0.0.0/0 0.0.0.0/0
- Chain FWDO_public_allow (1 references)
- target prot opt source destination
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate NEW,UNTRACKED
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate NEW,UNTRACKED
- Chain FWDO_public_deny (1 references)
- target prot opt source destination
- Chain FWDO_public_log (1 references)
- target prot opt source destination
- Chain INPUT_ZONES (1 references)
- target prot opt source destination
- IN_docker all -- 0.0.0.0/0 0.0.0.0/0 [goto]
- IN_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
- Chain INPUT_ZONES_SOURCE (1 references)
- target prot opt source destination
- Chain INPUT_direct (1 references)
- target prot opt source destination
- Chain IN_docker (1 references)
- target prot opt source destination
- IN_docker_log all -- 0.0.0.0/0 0.0.0.0/0
- IN_docker_deny all -- 0.0.0.0/0 0.0.0.0/0
- IN_docker_allow all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- Chain IN_docker_allow (1 references)
- target prot opt source destination
- Chain IN_docker_deny (1 references)
- target prot opt source destination
- Chain IN_docker_log (1 references)
- target prot opt source destination
- Chain IN_public (1 references)
- target prot opt source destination
- IN_public_log all -- 0.0.0.0/0 0.0.0.0/0
- IN_public_deny all -- 0.0.0.0/0 0.0.0.0/0
- IN_public_allow all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
- Chain IN_public_allow (1 references)
- target prot opt source destination
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:18888 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:18888 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpts:1887:1888 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:1887:1888 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:3306 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:10000 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:10000 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:1021 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:1021 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:443 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:443 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:15555 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:15555 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:94 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:94 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpts:39000:40000 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:39000:40000 ctstate NEW,UNTRACKED
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 ctstate NEW,UNTRACKED
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:80 ctstate NEW,UNTRACKED
- Chain IN_public_deny (1 references)
- target prot opt source destination
- Chain IN_public_log (1 references)
- target prot opt source destination
- Chain OUTPUT_direct (1 references)
- target prot opt source destination
- [root@cloud ~]#
- [root@cloud ~]# firewall-cmd --list-all
- You're performing an operation over default zone ('public'),
- but your connections/interfaces are in zone 'docker' (see --get-active-zones)
- You most likely need to use --zone=docker option.
- public
- target: default
- icmp-block-inversion: no
- interfaces:
- sources:
- services: dhcpv6-client ssh
- ports: 18888/tcp 18888/udp 1887-1888/tcp 1887-1888/udp 3306/tcp 3306/udp 10000/tcp 10000/udp 1021/tcp 1021/udp 443/tcp 443/udp 15555/tcp 15555/udp 94/tcp 94/udp 39000-40000/tcp 39000-40000/udp 80/tcp 80/udp
- protocols:
- masquerade: yes
- forward-ports:
- source-ports:
- icmp-blocks:
- rich rules:
-
复制代码 |