+ ip6tables -t raw -v -n -L Chain PREROUTING (policy ACCEPT 2741 packets, 14M bytes) pkts bytes target prot opt in out source destination 2741 14M neutron-openvswi-PREROUTING all -- * * ::/0 ::/0 Chain OUTPUT (policy ACCEPT 619 packets, 162K bytes) pkts bytes target prot opt in out source destination 619 162K neutron-openvswi-OUTPUT all -- * * ::/0 ::/0 Chain neutron-openvswi-OUTPUT (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-PREROUTING (1 references) pkts bytes target prot opt in out source destination + ip6tables -t mangle -v -n -L Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination + ip6tables -t nat -v -n -L Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 neutron-openvswi-PREROUTING all -- * * ::/0 ::/0 0 0 DOCKER all -- * * ::/0 ::/0 ADDRTYPE match dst-type LOCAL Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 350 packets, 28048 bytes) pkts bytes target prot opt in out source destination 0 0 DOCKER all -- * * ::/0 !::1 ADDRTYPE match dst-type LOCAL Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain DOCKER (2 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-PREROUTING (1 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-out tap5728a977-a3 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-in tap5728a977-a3 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-out tap724f1c1e-e9 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-in tap724f1c1e-e9 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-out tapb3c855fa-3b /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-in tapb3c855fa-3b /* Accept all packets when port is trusted. */ + ip6tables -t filter -v -n -L Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 1111 14M neutron-openvswi-INPUT all -- * * ::/0 ::/0 77491 1741M openstack-INPUT all -- * * ::/0 ::/0 Chain FORWARD (policy ACCEPT 88 packets, 6872 bytes) pkts bytes target prot opt in out source destination 88 6872 neutron-filter-top all -- * * ::/0 ::/0 88 6872 neutron-openvswi-FORWARD all -- * * ::/0 ::/0 88 6872 DOCKER-USER all -- * * ::/0 ::/0 88 6872 DOCKER-FORWARD all -- * * ::/0 ::/0 Chain OUTPUT (policy ACCEPT 50658 packets, 5914K bytes) pkts bytes target prot opt in out source destination 619 162K neutron-filter-top all -- * * ::/0 ::/0 619 162K neutron-openvswi-OUTPUT all -- * * ::/0 ::/0 Chain DOCKER (0 references) pkts bytes target prot opt in out source destination Chain DOCKER-BRIDGE (1 references) pkts bytes target prot opt in out source destination Chain DOCKER-CT (1 references) pkts bytes target prot opt in out source destination Chain DOCKER-FORWARD (1 references) pkts bytes target prot opt in out source destination 88 6872 DOCKER-CT all -- * * ::/0 ::/0 88 6872 DOCKER-INTERNAL all -- * * ::/0 ::/0 88 6872 DOCKER-BRIDGE all -- * * ::/0 ::/0 Chain DOCKER-INTERNAL (1 references) pkts bytes target prot opt in out source destination Chain DOCKER-USER (1 references) pkts bytes target prot opt in out source destination Chain neutron-filter-top (2 references) pkts bytes target prot opt in out source destination 707 168K neutron-openvswi-local all -- * * ::/0 ::/0 Chain neutron-openvswi-FORWARD (1 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-out tap5728a977-a3 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-in tap5728a977-a3 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-out tap724f1c1e-e9 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-in tap724f1c1e-e9 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-out tapb3c855fa-3b --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * ::/0 ::/0 PHYSDEV match --physdev-in tapb3c855fa-3b --physdev-is-bridged /* Accept all packets when port is trusted. */ Chain neutron-openvswi-INPUT (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-OUTPUT (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-local (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-sg-chain (0 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * ::/0 ::/0 Chain neutron-openvswi-sg-fallback (0 references) pkts bytes target prot opt in out source destination 0 0 DROP all -- * * ::/0 ::/0 /* Default drop rule for unmatched traffic. */ Chain openstack-INPUT (1 references) pkts bytes target prot opt in out source destination 20 1944 ACCEPT all -- lo * ::/0 ::/0 621 61376 ACCEPT ipv6-icmp -- * * ::/0 ::/0 0 0 ACCEPT tcp -- * * ::/0 ::/0 tcp dpt:22 76840 1741M ACCEPT all -- * * ::/0 ::/0 state RELATED,ESTABLISHED 0 0 ACCEPT tcp -- * * ::/0 ::/0 state NEW tcp dpt:19885 10 840 REJECT all -- * * ::/0 ::/0 reject-with icmp6-adm-prohibited