diff --git a/images/dind/node/iptables b/images/dind/node/iptables index 3684926f809c..4d0e9a57c4dc 100644 --- a/images/dind/node/iptables +++ b/images/dind/node/iptables @@ -11,6 +11,9 @@ # Ensure the master can talk to the kubelet -A INPUT -p tcp -m state --state NEW -m tcp --dport 10250 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT +-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT +-A INPUT -p tcp -m state --state NEW -m tcp --dport 1936 -j ACCEPT +-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT -A INPUT -j REJECT --reject-with icmp-host-prohibited -A FORWARD -j REJECT --reject-with icmp-host-prohibited COMMIT