istio.io/istio@v0.0.0-20240520182934-d79c90f27776/tools/istio-iptables/pkg/capture/testdata/inbound-ports-wildcard-tproxy.golden (about) 1 iptables -t nat -N ISTIO_INBOUND 2 iptables -t nat -N ISTIO_REDIRECT 3 iptables -t nat -N ISTIO_IN_REDIRECT 4 iptables -t mangle -N ISTIO_DIVERT 5 iptables -t mangle -N ISTIO_TPROXY 6 iptables -t mangle -N ISTIO_INBOUND 7 iptables -t nat -N ISTIO_OUTPUT 8 iptables -t nat -A ISTIO_INBOUND -p tcp --dport 15008 -j RETURN 9 iptables -t nat -A ISTIO_REDIRECT -p tcp -j REDIRECT --to-ports 15001 10 iptables -t nat -A ISTIO_IN_REDIRECT -p tcp -j REDIRECT --to-ports 15006 11 iptables -t mangle -A ISTIO_DIVERT -j MARK --set-mark 1337 12 iptables -t mangle -A ISTIO_DIVERT -j ACCEPT 13 iptables -t mangle -A ISTIO_TPROXY ! -d 127.0.0.1/32 -p tcp -j TPROXY --tproxy-mark 1337/0xffffffff --on-port 15006 14 iptables -t mangle -A PREROUTING -p tcp -j ISTIO_INBOUND 15 iptables -t mangle -A ISTIO_INBOUND -p tcp -m conntrack --ctstate RELATED,ESTABLISHED -j ISTIO_DIVERT 16 iptables -t mangle -A ISTIO_INBOUND -p tcp -j ISTIO_TPROXY 17 iptables -t nat -A OUTPUT -p tcp -j ISTIO_OUTPUT 18 iptables -t nat -A ISTIO_OUTPUT -o lo -s 127.0.0.6/32 -j RETURN 19 iptables -t nat -A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -p tcp ! --dport 15008 -m owner --uid-owner 1337 -j ISTIO_IN_REDIRECT 20 iptables -t nat -A ISTIO_OUTPUT -o lo -m owner ! --uid-owner 1337 -j RETURN 21 iptables -t nat -A ISTIO_OUTPUT -m owner --uid-owner 1337 -j RETURN 22 iptables -t nat -A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -p tcp ! --dport 15008 -m owner --gid-owner 1337 -j ISTIO_IN_REDIRECT 23 iptables -t nat -A ISTIO_OUTPUT -o lo -m owner ! --gid-owner 1337 -j RETURN 24 iptables -t nat -A ISTIO_OUTPUT -m owner --gid-owner 1337 -j RETURN 25 iptables -t nat -A ISTIO_OUTPUT -d 127.0.0.1/32 -j RETURN 26 iptables -t mangle -A PREROUTING -p tcp -m mark --mark 1337 -j CONNMARK --save-mark 27 iptables -t mangle -A OUTPUT -p tcp -o lo -m mark --mark 1337 -j RETURN 28 iptables -t mangle -A OUTPUT ! -d 127.0.0.1/32 -p tcp -o lo -m owner --uid-owner 1337 -j MARK --set-mark 1338 29 iptables -t mangle -A OUTPUT ! -d 127.0.0.1/32 -p tcp -o lo -m owner --gid-owner 1337 -j MARK --set-mark 1338 30 iptables -t mangle -A OUTPUT -p tcp -m connmark --mark 1337 -j CONNMARK --restore-mark 31 iptables -t mangle -I ISTIO_INBOUND 1 -p tcp -m mark --mark 1337 -j RETURN 32 iptables -t mangle -I ISTIO_INBOUND 2 -p tcp -s 127.0.0.6/32 -i lo -j RETURN 33 iptables -t mangle -I ISTIO_INBOUND 3 -p tcp -i lo -m mark ! --mark 1338 -j RETURN 34 iptables-save