user@debian:~$ sudo docker network create test 675fd604ad6216f36401742edb11422fa2a57bbfb08e821187b4405c0f08b747
In dockerd debug logs, we get lines like: " level=debug msg="/usr/sbin/iptables, [--wait -t filter -C FORWARD -i br-675fd604ad62 -o br-675fd604ad62 -j DROP]" " level=debug msg="/usr/sbin/iptables, [--wait -t filter -C FORWARD -i br-675fd604ad62 -o br-675fd604ad62 -j ACCEPT]" " level=debug msg="/usr/sbin/iptables, [--wait -t filter -C FORWARD -i br-675fd604ad62 ! -o br-675fd604ad62 -j ACCEPT]" Running them manually yields: user@debian:~$ sudo iptables -C FORWARD -i br-675fd60 -o br-675fd60 -j ACCEPT user@debian:~$ echo $? 0 user@debian:~$ sudo iptables -v -C FORWARD -i br-675fd60 -o br-675fd60 -j ACCEPT ACCEPT all opt -- in docker0 out docker0 0.0.0.0/0 -> 0.0.0.0/0