docker network create -o "com.docker.network.bridge.enable_ip_masquerade"="false" lan-restricted
Blocks
Local LAN
Internet
Does not block
Host running docker daemon (example access to 10.0.1.10:22)
docker network create -o "com.docker.network.bridge.enable_icc"="false" icc-restricted
Blocks
Containers accessing other containers on the same icc-restricted network.
Does not block
Access to host running docker daemon
Local LAN
Internet
iptables -I INPUT -i docker0 -m addrtype --dst-type LOCAL -j DROP
Blocks
Access to host running docker daemon
Does not block
Container to container traffic
Local LAN
Internet
Custom docker networks that doesn't use docker0