
Distros often have additional rules in the their iptabvles 'filter' table that do things like: -A FORWARD -j REJECT --reject-with icmp-host-prohibited docker, for example, gets around this by adding explicit rules to the filter table's FORWARD chain to allow traffic from the docker0 interface. Do that for a given host interface too, as a chained plugin.
13 lines
247 B
Plaintext
13 lines
247 B
Plaintext
plugins/ipam/dhcp
|
|
plugins/main/bridge
|
|
plugins/main/host-device
|
|
plugins/main/ipvlan
|
|
plugins/main/loopback
|
|
plugins/main/macvlan
|
|
plugins/main/ptp
|
|
plugins/main/vlan
|
|
plugins/meta/portmap
|
|
plugins/meta/tuning
|
|
plugins/meta/bandwidth
|
|
plugins/meta/firewall
|