+ iptables -t raw -v -n -L Chain PREROUTING (policy ACCEPT 799K packets, 713M bytes) pkts bytes target prot opt in out source destination 799K 713M neutron-openvswi-PREROUTING all -- * * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy ACCEPT 797K packets, 690M bytes) pkts bytes target prot opt in out source destination 797K 690M neutron-openvswi-OUTPUT all -- * * 0.0.0.0/0 0.0.0.0/0 Chain neutron-openvswi-OUTPUT (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-PREROUTING (1 references) pkts bytes target prot opt in out source destination + iptables -t mangle -v -n -L Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination + iptables -t nat -v -n -L Chain PREROUTING (policy ACCEPT 2986 packets, 719K bytes) pkts bytes target prot opt in out source destination 2986 719K neutron-openvswi-PREROUTING all -- * * 0.0.0.0/0 0.0.0.0/0 Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain neutron-openvswi-PREROUTING (1 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-out tap5728a977-a3 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-in tap5728a977-a3 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-out tap724f1c1e-e9 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-in tap724f1c1e-e9 /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-out tapb3c855fa-3b /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-in tapb3c855fa-3b /* Accept all packets when port is trusted. */ + iptables -t filter -v -n -L Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 798K 713M neutron-openvswi-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- br-0 * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- vxlan-0 * 0.0.0.0/0 0.0.0.0/0 44592 142M ACCEPT all -- * * 199.204.45.109 0.0.0.0/0 1098K 3269M openstack-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0 Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 neutron-filter-top all -- * * 0.0.0.0/0 0.0.0.0/0 0 0 neutron-openvswi-FORWARD all -- * * 0.0.0.0/0 0.0.0.0/0 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 4 prefix "iptables FORWARD: " Chain OUTPUT (policy ACCEPT 1112K packets, 3159M bytes) pkts bytes target prot opt in out source destination 797K 690M neutron-filter-top all -- * * 0.0.0.0/0 0.0.0.0/0 797K 690M neutron-openvswi-OUTPUT all -- * * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- * br-0 0.0.0.0/0 0.0.0.0/0 1286 52180 ACCEPT all -- * vxlan-0 0.0.0.0/0 0.0.0.0/0 Chain neutron-filter-top (2 references) pkts bytes target prot opt in out source destination 797K 690M neutron-openvswi-local all -- * * 0.0.0.0/0 0.0.0.0/0 Chain neutron-openvswi-FORWARD (1 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-out tap5728a977-a3 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-in tap5728a977-a3 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-out tap724f1c1e-e9 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-in tap724f1c1e-e9 --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-out tapb3c855fa-3b --physdev-is-bridged /* Accept all packets when port is trusted. */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-in tapb3c855fa-3b --physdev-is-bridged /* Accept all packets when port is trusted. */ Chain neutron-openvswi-INPUT (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-OUTPUT (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-local (1 references) pkts bytes target prot opt in out source destination Chain neutron-openvswi-sg-chain (0 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 Chain neutron-openvswi-sg-fallback (0 references) pkts bytes target prot opt in out source destination 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* Default drop rule for unmatched traffic. */ Chain openstack-INPUT (1 references) pkts bytes target prot opt in out source destination 1061K 3015M ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 22 1676 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 255 10770 22M ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 24804 232M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 94 5640 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:19885 0 0 ACCEPT udp -- * * 172.24.4.0/23 0.0.0.0/0 udp dpt:69 0 0 ACCEPT tcp -- * * 172.24.4.0/23 0.0.0.0/0 tcp dpt:6385 0 0 ACCEPT tcp -- * * 172.24.4.0/23 0.0.0.0/0 tcp dpt:80 0 0 ACCEPT tcp -- * * 172.24.4.0/23 0.0.0.0/0 tcp dpt:8000 0 0 ACCEPT tcp -- * * 172.24.4.0/23 0.0.0.0/0 tcp dpt:8003 0 0 ACCEPT tcp -- * * 172.24.4.0/23 0.0.0.0/0 tcp dpt:8004 88 10008 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 2/min burst 5 LOG flags 0 level 4 prefix "iptables dropped: " 1140 242K REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited