你看一下 iptables -nvL -t nat
看有沒有
Chain PREROUTING (policy ACCEPT 8962K packets, 6820M bytes)
pkts bytes target prot opt in out source destination
1592K 92M DOCKER all -- * *
0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type LOCAL
Chain POSTROUTING (policy ACCEPT 358K packets, 50M bytes)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * !docker0
172.17.0.0/16 0.0.0.0/0 0 0 ACCEPT esp -- * *
0.0.0.0/0 0.0.0.0/0Chain DOCKER (2 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- docker0 *
0.0.0.0/0 0.0.0.0/0