Re: Problems accessing host from docker container running on host
Sean Murphy via Shorewall-users <[email protected]> Thu, 20 Mar 2025 08:28:32 +0000
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <ZR1P278MB1222831953954C70D8B5F43897D82@ZR1P278MB1222.CHEP278.PROD.OUTLOOK.COM> |
Thanks Matt. Yes - if I do a shorewall clear, it's possible to access the host from insi= de the docker container. The default docker iptables config seems to support this. However, when I enabl= e shorewall (with docker support), it's not possible. It really seems like some interaction between the docker iptables functiona= lity and the shorewall iptables functionality is causing the problem and more specifically, on the= return path from the service running on the host to the docker container. It could be something of an edge case as mostly the point of having contain= ers is to have (some) = isolation from the host but we think it prob should be possible to eg acces= s stuff from inside the = containers which is accessible from anywhere on the internet. Thanks for any insights. BR, Sean. __________________________________ Sean Murphy Senior Platform Engineer [email protected] T +41 44=A0 289-84-22 www.datahouse.ch Linkedin=A0| YouTube __________________________________ ________________________________________ From:=A0Matt Darfeuille <[email protected]> Sent:=A0Wednesday, March 19, 2025 8:19 PM To:[email protected] <[email protected]= rge.net> Subject:=A0Re: [Shorewall-users] Problems accessing host from docker contai= ner running on host =A0 [You don't often get email from [email protected]. Learn why this is impor= tant at https://aka.ms/LearnAboutSenderIdentification=A0] On 3/19/25 10:49, Sean Murphy via Shorewall-users wrote: > Hi all,, > > We have been (ab)using shorewall for some years now and we're v happy wit= h it - > thanks everyone and Tom in particular for such a great tool. > > We have been using it to manage security for a set of VMs running applica= tions > with docker-compose. Almost all of our hosts have a single external netwo= rk > interface; this is perhaps not the use case for which shorewall was desig= ned > but it has been working for us so far. > > We now have a scenario which is proving more difficult: we want to access= a > service running on a host from within a container. > > We have tried the most open configuration possible - a policy with all:all > ACCEPT and no rules; it seems the service is accessible from anywhere exc= ept > inside the docker container. > > Accessing the service from inside the container results in timeouts, so p= resumably > the packets are being dropped somewhere. We tried ping, ssh (on standard = ports) > and an http service running on a high port number. > > Zone configuration: > root@dhit-disposable01:/etc/shorewall# cat zones > #########################################################################= ###### > #ZONE=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 TYPE=A0=A0=A0=A0=A0 OPTIONS=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 IN=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OUT > #=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OP= TIONS=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OPTIONS > fw=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 firewall > net=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 ipv4 > dock=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 ipv4 > > Interface configuration: > root@dhit-disposable01:/etc/shorewall# cat interfaces > #########################################################################= ###### > ?FORMAT 2 > #########################################################################= ###### > #ZONE=A0=A0 INTERFACE=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OPT= IONS > net=A0=A0=A0=A0 eth=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0 physical=3Deth+,dhcp,nosmurfs > net=A0=A0=A0=A0 en=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0 physical=3Den+,dhcp,nosmurfs > dock=A0=A0=A0 docker0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0 physical=3Ddocker+,routeback=3D1 > dock=A0=A0=A0 br=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0 physical=3Dbr-+,routeback=3D1 > > Policy configuration: > root@dhit-disposable01:/etc/shorewall# cat policy > #SOURCE=A0=A0=A0=A0=A0=A0=A0 DEST=A0=A0=A0=A0=A0=A0=A0 POLICY=A0=A0=A0=A0= =A0 LOGLEVEL=A0=A0=A0 LIMIT > all=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 all=A0=A0=A0=A0=A0=A0=A0=A0 ACCEPT > > Rules configuration: > root@dhit-disposable01:/etc/shorewall# cat rules > #ACTION=A0=A0=A0=A0=A0 SOURCE=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0 DEST=A0=A0=A0=A0=A0=A0 PROTO=A0=A0=A0=A0=A0 DPORT > # No rules > > Docker configuration as per shorewall.conf > root@dhit-disposable01:/etc/shorewall# grep -i docker shorewall.conf > # Default shorewall config, except for DOCKER=3DYes (and this comment). > DOCKER=3DYes > DOCKER_BRIDGE=3Ddocker0 > > I did shorewall compile, safe-reload and then restarted the docker deamon= but > the packets still seem to be being dropped. I tried iptables-tracer [1] t= o get some > info on where they disappear and it seems packets are being dropped on the > return path. If you do a `shorewall clear`, does it work at all? Note that the project is unmaintained. -- Matt Darfeuille <[email protected]> Unmaintained project, no more releases or bug fixes Community: https://sourceforge.net/p/shorewall/mailman/message/37107049/ _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users