root@docker:/srv/dock# iptables -L -n -t nat
Chain PREROUTING (policy ACCEPT)
target prot opt source destination
DOCKER all -- 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type LOCAL
Chain INPUT (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
DOCKER all -- 0.0.0.0/0 !127.0.0.0/8 ADDRTYPE match dst-type LOCAL
Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
MASQUERADE all -- 10.100.0.0/24 0.0.0.0/0
SNAT all -- 172.17.0.0/16 0.0.0.0/0 to:192.168.58.132
MASQUERADE tcp -- 10.100.0.3 10.100.0.3 tcp dpt:11211
MASQUERADE tcp -- 10.100.0.4 10.100.0.4 tcp dpt:3306
MASQUERADE tcp -- 10.100.0.2 10.100.0.2 tcp dpt:9000
MASQUERADE tcp -- 10.100.0.5 10.100.0.5 tcp dpt:443
MASQUERADE tcp -- 10.100.0.5 10.100.0.5 tcp dpt:80
Chain DOCKER (2 references)
target prot opt source destination
RETURN all -- 0.0.0.0/0 0.0.0.0/0
RETURN all -- 0.0.0.0/0 0.0.0.0/0
DNAT tcp -- 0.0.0.0/0 192.168.58.132 tcp dpt:11211 to:10.100.0.3:11211
DNAT tcp -- 0.0.0.0/0 192.168.58.132 tcp dpt:3306 to:10.100.0.4:3306
DNAT tcp -- 0.0.0.0/0 192.168.58.132 tcp dpt:9000 to:10.100.0.2:9000
DNAT tcp -- 0.0.0.0/0 192.168.58.132 tcp dpt:443 to:10.100.0.5:443
DNAT tcp -- 0.0.0.0/0 192.168.58.132 tcp dpt:80 to:10.100.0.5:80
Алексей Ярков,