- swinchen@cloudy:~$ sudo iptables -vn -L
- [sudo] password for swinchen:
- Chain INPUT (policy ACCEPT 17476 packets, 9688K bytes)
- pkts bytes target prot opt in out source destination
- 17782 9719K nova-network-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- 17596 9698K nova-compute-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- 17596 9698K nova-api-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
- 0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
- 0 0 ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:67
- 0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:67
- Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 90447 167M nova-filter-top all -- * * 0.0.0.0/0 0.0.0.0/0
- 46230 3923K nova-network-FORWARD all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 nova-compute-FORWARD all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 nova-api-FORWARD all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * virbr0 0.0.0.0/0 192.168.122.0/24 state RELATED,ESTABLISHED
- 0 0 ACCEPT all -- virbr0 * 192.168.122.0/24 0.0.0.0/0
- 0 0 ACCEPT all -- virbr0 virbr0 0.0.0.0/0 0.0.0.0/0
- 0 0 REJECT all -- * virbr0 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- virbr0 * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
- Chain OUTPUT (policy ACCEPT 16993 packets, 9661K bytes)
- pkts bytes target prot opt in out source destination
- 17317 9710K nova-filter-top all -- * * 0.0.0.0/0 0.0.0.0/0
- 16993 9661K nova-network-OUTPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- 16993 9661K nova-compute-OUTPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- 16993 9661K nova-api-OUTPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-api-FORWARD (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-api-INPUT (1 references)
- pkts bytes target prot opt in out source destination
- 120 10118 ACCEPT tcp -- * * 0.0.0.0/0 10.20.0.1 tcp dpt:8775
- Chain nova-api-OUTPUT (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-api-local (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-FORWARD (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- br1 * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * br1 0.0.0.0/0 0.0.0.0/0
- Chain nova-compute-INPUT (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-OUTPUT (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-inst-5 (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
- 44516 163M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 25 1671 nova-compute-provider all -- * * 0.0.0.0/0 0.0.0.0/0
- 1 339 ACCEPT udp -- * * 192.168.1.1 0.0.0.0/0 udp spt:67 dpt:68
- 4 240 ACCEPT all -- * * 192.168.1.0/24 0.0.0.0/0
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
- 3 164 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
- 12 636 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
- 5 292 nova-compute-sg-fallback all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-compute-local (1 references)
- pkts bytes target prot opt in out source destination
- 44541 163M nova-compute-inst-5 all -- * * 0.0.0.0/0 192.168.1.3
- Chain nova-compute-provider (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-sg-fallback (1 references)
- pkts bytes target prot opt in out source destination
- 5 292 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-filter-top (2 references)
- pkts bytes target prot opt in out source destination
- 108K 177M nova-network-local all -- * * 0.0.0.0/0 0.0.0.0/0
- 108K 177M nova-compute-local all -- * * 0.0.0.0/0 0.0.0.0/0
- 63223 14M nova-api-local all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-network-FORWARD (1 references)
- pkts bytes target prot opt in out source destination
- 46230 3923K ACCEPT all -- br1 * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * br1 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.1.2 udp dpt:1194
- Chain nova-network-INPUT (1 references)
- pkts bytes target prot opt in out source destination
- 35 11480 ACCEPT udp -- br1 * 0.0.0.0/0 0.0.0.0/0 udp dpt:67
- 0 0 ACCEPT tcp -- br1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:67
- 151 10154 ACCEPT udp -- br1 * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
- 0 0 ACCEPT tcp -- br1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
- Chain nova-network-OUTPUT (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-network-local (1 references)
- pkts bytes target prot opt in out source destination