# Generated by iptables-save v1.8.4 on Thu Jan 26 10:16:50 2023 *filter :INPUT ACCEPT [49376:66199370] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [42281:9869570] :KUBE-FIREWALL - [0:0] :KUBE-KUBELET-CANARY - [0:0] -A INPUT -j KUBE-FIREWALL -A OUTPUT -j KUBE-FIREWALL -A KUBE-FIREWALL ! -s 127.0.0.0/8 -d 127.0.0.0/8 -m comment --comment "block incoming localnet connections" -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT -j DROP -A KUBE-FIREWALL -m comment --comment "kubernetes firewall for dropping marked packets" -m mark --mark 0x8000/0x8000 -j DROP COMMIT # Completed on Thu Jan 26 10:16:50 2023 # Generated by iptables-save v1.8.4 on Thu Jan 26 10:16:50 2023 *security :INPUT ACCEPT [49387:66201792] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [42284:9869726] COMMIT # Completed on Thu Jan 26 10:16:50 2023 # Generated by iptables-save v1.8.4 on Thu Jan 26 10:16:50 2023 *raw :PREROUTING ACCEPT [49394:66200408] :OUTPUT ACCEPT [42284:9869726] COMMIT # Completed on Thu Jan 26 10:16:50 2023 # Generated by iptables-save v1.8.4 on Thu Jan 26 10:16:50 2023 *mangle :PREROUTING ACCEPT [49394:66200408] :INPUT ACCEPT [49377:66199422] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [42284:9869726] :POSTROUTING ACCEPT [42284:9869726] :KUBE-IPTABLES-HINT - [0:0] :KUBE-KUBELET-CANARY - [0:0] COMMIT # Completed on Thu Jan 26 10:16:50 2023 # Generated by iptables-save v1.8.4 on Thu Jan 26 10:16:50 2023 *nat :PREROUTING ACCEPT [56:6752] :INPUT ACCEPT [18:1136] :POSTROUTING ACCEPT [343:22689] :OUTPUT ACCEPT [702:44229] :OVN-KUBE-SNAT-MGMTPORT - [0:0] :KUBE-MARK-DROP - [0:0] :KUBE-MARK-MASQ - [0:0] :KUBE-POSTROUTING - [0:0] :KUBE-KUBELET-CANARY - [0:0] :OVN-KUBE-NODEPORT - [0:0] -A POSTROUTING -m comment --comment "kubernetes postrouting rules" -j KUBE-POSTROUTING -A POSTROUTING -o ovn-k8s-mp0 -j OVN-KUBE-SNAT-MGMTPORT -A OVN-KUBE-SNAT-MGMTPORT -o ovn-k8s-mp0 -m comment --comment "OVN SNAT to Management Port" -j SNAT --to-source 10.42.0.2 -A KUBE-MARK-DROP -j MARK --set-xmark 0x8000/0x8000 -A KUBE-MARK-MASQ -j MARK --set-xmark 0x4000/0x4000 -A KUBE-POSTROUTING -m mark ! --mark 0x4000/0x4000 -j RETURN -A KUBE-POSTROUTING -j MARK --set-xmark 0x4000/0x0 -A KUBE-POSTROUTING -m comment --comment "kubernetes service traffic requiring SNAT" -j MASQUERADE --random-fully -A OVN-KUBE-NODEPORT -p tcp -m addrtype --dst-type LOCAL -m tcp --dport 31716 -j DNAT --to-destination 10.43.47.31:8080 COMMIT # Completed on Thu Jan 26 10:16:50 2023