docker学习笔记之七:解决 -i docker0: iptables: No chain/target/match by that name.

启动容器时,有可能会遇到以下问题,好比启动redis容器:linux

sudo docker run -d -p 6379:6379 --name redis redis:latestredis

docker: Error response from daemon: failed to create endpoint redis on network bridge: iptables failed: iptables --wait -t nat -A DOCKER -p tcp -d 10.211.55.9 --dport 6379 -j DNAT --to-destination 172.17.0.4:6379 ! -i docker0: iptables: No chain/target/match by that name.
 (exit status 1).

 

经过分析异常信息,发现是由于在进行原地址到目标地址转换的时候没有在docker主机的iptables规则中找到nat表规则,只有filter表规则。docker

 

在filter表上面增长nat表配置规则信息,须要说明的是docker容器的网段是172.17.0.0/16,另外须要注意filter表中也要有docker链的相关配置。shell

sudo vi /etc/sysconfig/iptablestcp

  1. # sample configuration for iptables service
    # you can edit this manually or use system-config-firewall
    # please do not ask us to add additional ports/services to this default configuration
    *nat
    :PREROUTING ACCEPT [27:11935]
    :INPUT ACCEPT [0:0]
    :OUTPUT ACCEPT [0:0]
    :POSTROUTING ACCEPT [0:0]
    :DOCKER -[0:0]
    -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
    -A OUTPUT !-d 127.0.0.0/8-m addrtype --dst-type LOCAL -j DOCKER
    -A POSTROUTING -s 172.17.0.0/16!-o docker0 -j MASQUERADE
    COMMIT
    #
    *filter
    :INPUT ACCEPT [0:0]
    :FORWARD ACCEPT [0:0]
    :OUTPUT ACCEPT [0:0]
    :DOCKER -[0:0]
    -A FORWARD -o docker0 -j DOCKER
    -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    -A FORWARD -i docker0 !-o docker0 -j ACCEPT
    -A FORWARD -i docker0 -o docker0 -j ACCEPT
    -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
    -A INPUT -p icmp -j ACCEPT
    -A INPUT -i lo -j ACCEPT
    -A INPUT -p tcp -m state --state NEW -m tcp --dport 22-j ACCEPT
    -A INPUT -p tcp -m state --state NEW -m tcp --dport 9090-j ACCEPT
    -A INPUT -p tcp -m state --state NEW -m tcp --dport 1521-j ACCEPT
    -A INPUT -p tcp -m state --state NEW -m tcp --dport 6379-j ACCEPT
    -A INPUT -j REJECT --reject-with icmp-host-prohibited
    -A FORWARD -j REJECT --reject-with icmp-host-prohibited
    COMMIT
     

重启iptablesthis

sudo systemctl restart iptables.service spa

 

从新启动容器便可。rest