The `--userland-proxy` daemon flag makes it possible to rely on hairpin NAT and additional iptables routes instead of userland proxy for port publishing and inter-container communication. Usage of the userland proxy remains the default as hairpin NAT is unsupported by older kernels. Signed-off-by: Arnaud Porterie <arnaud.porterie@docker.com> |
||
|---|---|---|
| .. | ||
| firewalld.go | ||
| firewalld_test.go | ||
| iptables.go | ||
| iptables_test.go | ||