# sudo iptables -nvL# --icc=trueChain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target     prot opt in     out     source               destination             0     0 DOCKER-USER  all  --  *      *       0.0.0.0/0            0.0.0.0/0               0     0 DOCKER-ISOLATION-STAGE-1  all  --  *      *       0.0.0.0/0            0.0.0.0/0               0     0 ACCEPT     all  --  *      docker0  0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED    0     0 DOCKER     all  --  *      docker0  0.0.0.0/0            0.0.0.0/0               0     0 ACCEPT     all  --  docker0 !docker0  0.0.0.0/0            0.0.0.0/0           # 此处输出发生了变化,从docker0到docker0的包,是ACCEPT    0     0 ACCEPT     all  --  docker0 docker0  0.0.0.0/0            0.0.0.0/0             
# --icc=falseChain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target     prot opt in     out     source               destination             0     0 DOCKER-USER  all  --  *      *       0.0.0.0/0            0.0.0.0/0               0     0 DOCKER-ISOLATION-STAGE-1  all  --  *      *       0.0.0.0/0            0.0.0.0/0               0     0 ACCEPT     all  --  *      docker0  0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED    0     0 DOCKER     all  --  *      docker0  0.0.0.0/0            0.0.0.0/0               0     0 ACCEPT     all  --  docker0 !docker0  0.0.0.0/0            0.0.0.0/0           # 此处输出发生了变化,从docker0到docker0的包,变成了DROP    0     0 DROP       all  --  docker0 docker0  0.0.0.0/0            0.0.0.0/0        
评论