# Generated by iptables-save v1.4.21 on Thu Jan 21 19:43:06 2021
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [8:534]
:POSTROUTING ACCEPT [8:534]
:DOCKER - [0:0]
-A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
-A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
-A POSTROUTING -s 172.18.0.0/16 ! -o docker0 -j MASQUERADE
-A DOCKER -i docker0 -j RETURN
COMMIT
# Completed on Thu Jan 21 19:43:06 2021
# Generated by iptables-save v1.4.21 on Thu Jan 21 19:43:06 2021
*filter
:INPUT ACCEPT [1378:92671]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [1359:272780]
:DOCKER - [0:0]
:DOCKER-ISOLATION - [0:0]
-A INPUT -p tcp --dport 22 -j ACCEPT
-A INPUT -p tcp --dport 80 -j ACCEPT
-A INPUT -p tcp --dport 3306 -j ACCEPT
-A FORWARD -j DOCKER-ISOLATION
-A FORWARD -o docker0 -j DOCKER
-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i docker0 ! -o docker0 -j ACCEPT
-A FORWARD -i docker0 -o docker0 -j ACCEPT
-A DOCKER-ISOLATION -j RETURN
COMMIT
# Completed on Thu Jan 21 19:43:06 2021
查看防火墙开放端口
iptables -nL --line-number
查看防火墙状态
systemctl status iptables
安装iptables
yum install iptables-services
启动iptables
systemctl enable iptables
systemctl start iptables