安装了Docker的机器,暴力执行iptables -F,会导致docker的规则全清,无法访问pod服务,暴力方法是重启docker, 或者重新添加一下docker的规则即可.
iptables -A FORWARD -j DOCKER-ISOLATION
iptables -A FORWARD -o docker0 -j DOCKER
# iptables -A DOCKER-ISOLATION -j RETURN
iptables -A FORWARD -o docker0 -j DOCKER
iptables -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
iptables -A FORWARD -i docker0 -o docker0 -j ACCEPT