$ docker run --cap-add=NET_ADMIN --rm -ti hoge_image /bin/bash bash-4.1# echo 'IPTABLES_MODULES_UNLOAD=no' >> /etc/sysconfig/iptables-config bash-4.1# service iptables stop iptables: Setting chains to policy ACCEPT: nat filter [ OK ] iptables: Flushing firewall rules: [ OK ] bash-4.1# service iptables status Table: nat Chain PREROUTING (policy ACCEPT) num target prot opt source destination Chain I