List the active firewall rules on Ubuntu
Three views of one ruleset on Ubuntu: nft list ruleset, iptables -L -n -v and ufw status. Find shadowed rules with counters and see why Docker skips ufw.
Filtering by topic #iptables · clear
Three views of one ruleset on Ubuntu: nft list ruleset, iptables -L -n -v and ufw status. Find shadowed rules with counters and see why Docker skips ufw.
On Ubuntu the iptables command already writes nftables rules. Prove it on your box, read the native ruleset, and see where ufw and Docker collide.
Docker publishes container ports with iptables rules that skip UFW, so a denied port still answers the internet. See the mechanism and the fixes that work.