root@kubernetes-master co]# iptables -LChain INPUT (policy ACCEPT)target prot opt source destination KUBE-SERVICES all -- anywhere anywhere ctstate NEW /* kubernetes service portals */KUBE-EXTERNAL-SERVICES all -- anywhere anywhere ctstate NEW /* kubernetes externally-visible service portals */KUBE-FIREWALL all -- anywhere anywhere Chain FORWARD (policy ACCEPT)target prot opt source destination KUBE-FORWARD all -- anywhere anywhere /* kubernetes forwarding rules */KUBE-SERVICES all -- anywhere anywhere ctstate NEW /* kubernetes service portals */DOCKER-USER all -- anywhere anywhere DOCKER-ISOLATION-STAGE-1 all -- anywhere anywhere ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHEDDOCKER all -- anywhere anywhere ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere ACCEPT all -- 10.244.0.0/16 anywhere ACCEPT all -- anywhere 10.244.0.0/16 Chain OUTPUT (policy ACCEPT)target prot opt source destination KUBE-SERVICES all -- anywhere anywhere ctstate NEW /* kubernetes service portals */KUBE-FIREWALL all -- anywhere anywhere Chain DOCKER (1 references)target prot opt source destination Chain DOCKER-ISOLATION-STAGE-1 (1 references)target prot opt source destination DOCKER-ISOLATION-STAGE-2 all -- anywhere anywhere RETURN all -- anywhere anywhere Chain DOCKER-ISOLATION-STAGE-2 (1 references)target prot opt source destination DROP all -- anywhere anywhere RETURN all -- anywhere anywhere Chain DOCKER-USER (1 references)target prot opt source destination RETURN all -- anywhere anywhere Chain KUBE-EXTERNAL-SERVICES (1 references)target prot opt source destination Chain KUBE-FIREWALL (2 references)target prot opt source destination DROP all -- anywhere anywhere /* kubernetes firewall for dropping marked packets */ mark match 0x8000/0x8000DROP all -- !loopback/8 loopback/8 /* block incoming localnet connections */ ! ctstate RELATED,ESTABLISHED,DNATChain KUBE-FORWARD (1 references)target prot opt source destination DROP all -- anywhere anywhere ctstate INVALIDACCEPT all -- anywhere anywhere /* kubernetes forwarding rules */ mark match 0x4000/0x4000ACCEPT all -- anywhere anywhere /* kubernetes forwarding conntrack pod source rule */ ctstate RELATED,ESTABLISHEDACCEPT all -- anywhere anywhere /* kubernetes forwarding conntrack pod destination rule */ ctstate RELATED,ESTABLISHEDChain KUBE-KUBELET-CANARY (0 references)target prot opt source destination Chain KUBE-PROXY-CANARY (0 references)target prot opt source destination Chain KUBE-SERVICES (3 references)target prot opt source destination [root@kubernetes-master co]#