Scene
- Run a container
docker run --dit --name mynginx -p 7070:80 nginx
the mynginx container get an IP 172.17.0.9
- The Automatically added rules
iptables-save |grep 172.17.0.9
...
-A POSTROUTING -s 172.17.0.9/32 -d 172.17.0.9/32 -p tcp -m tcp --dport 80 -j MASQUERADE
-A DOCKER ! -i docker0 -p tcp -m tcp --dport 7070 -j DNAT --to-destination 172.17.0.9:80
-A DOCKER -d 172.17.0.9/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 80 -j ACCEPT
...
How to understand this rule
-A POSTROUTING -s 172.17.0.9/32 -d 172.17.0.9/32 -p tcp -m tcp --dport 80 -j MASQUERADE
source and destination are the same in this rule, which case does it work.