You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器内查看主机iptables异常问题求助

问题:Docker容器内无法查看主机iptables规则(Ubuntu 22.04主机+≤20.04容器场景)

需要在Docker容器内以只读权限查看主机iptables规则,已配置--cap-add=NET_ADMIN并设置network=host,但容器内iptables显示为空,容器内添加规则也不影响主机,容器与主机的iptables规则完全不同。

主机执行命令输出

root@host:~# iptables -xnvL OUTPUT 
# Warning: iptables-legacy tables present, use iptables-legacy to see them
Chain OUTPUT (policy ACCEPT 1104394 packets, 407916631 bytes)
    pkts      bytes target     prot opt in     out     source               destination         
   16498  3125381            all  --  *      *       8.8.8.8         0.0.0.0/0           
  107211 59743643            all  --  *      *       192.168.0.1          0.0.0.0/0           

容器内执行命令输出

root@host:~# docker exec ct_monitor_1 iptables -xnvL OUTPUT
Chain OUTPUT (policy ACCEPT 33081662 packets, 12617923760 bytes)
    pkts      bytes target     prot opt in     out     source               destination         
  206142 41989385            all  --  *      *       1.1.1.1         0.0.0.0/0           
 3686279 1919571839            all  --  *      *       172.0.0.1          0.0.0.0/0

(规则为示例,仅用于展示容器与主机iptables不同)


场景限定

该问题仅出现在Ubuntu 22.04主机搭配≤20.04版本Ubuntu容器的场景中。

主机环境信息

root@host:~# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 22.04.1 LTS
Release:        22.04
Codename:       jammy

root@zitz:~# iptables -nvL OUTPUT
# Warning: iptables-legacy tables present, use iptables-legacy to see them
Chain OUTPUT (policy ACCEPT 437K packets, 229M bytes)
 pkts bytes target     prot opt in     out     source               destination         
 285K  142M            all  --  *      *       8.8.8.8         0.0.0.0/0           
 120K   83M            all  --  *      *       192.168.0.1          0.0.0.0/0

正常示例(使用ubuntu:jammy-20221003容器)

root@zitz:~# docker run --rm -it --network=host --cap-add=NET_ADMIN ubuntu:jammy-20221003 bash
root@zitz:/# apt -qq -y update && apt install -qq -y iptables
root@zitz:/# iptables -nvL OUTPUT
# Warning: iptables-legacy tables present, use iptables-legacy to see them
Chain OUTPUT (policy ACCEPT 436K packets, 229M bytes)
 pkts bytes target     prot opt in     out     source               destination         
 285K  142M            all  --  *      *       8.8.8.8         0.0.0.0/0           
 120K   82M            all  --  *      *       192.168.0.1          0.0.0.0/0

异常示例(使用≤20.04版本Ubuntu容器)

root@zitz:~# docker run --rm -it --network=host --cap-add=NET_ADMIN ubuntu:focal bash
root@zitz:/# apt -qq update && apt install -y -qqq iptables
.
.
.
root@zitz:/# iptables -nvL OUTPUT
Chain OUTPUT (policy ACCEPT 148K packets, 53M bytes)
 pkts bytes target     prot opt in     out     source               destination

原因分析

Ubuntu 22.04默认采用iptables-nft(基于nftables的iptables兼容层),但主机中同时存在iptables-legacy规则;而≤20.04版本的Ubuntu容器默认使用iptables-legacy,当容器以host网络模式运行时,容器内的iptables-legacy无法读取主机上的iptables-nft规则表,因此显示为空。

解决方法

方法1:切换容器内iptables后端为nft

在容器内执行以下命令:

# 安装iptables-nft包
apt install -y iptables-nft
# 设置默认iptables后端为nft
update-alternatives --set iptables /usr/sbin/iptables-nft
# 验证是否能查看主机规则
iptables -xnvL OUTPUT

方法2:直接使用iptables-legacy查看主机legacy规则

如果主机确实存在iptables-legacy规则,可在容器内直接执行:

iptables-legacy -xnvL OUTPUT

内容的提问来源于stack exchange,提问作者Roberto Iglesias

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 21:01:22