Re: Problems accessing host from docker container running on host

Sean Murphy via Shorewall-users <[email protected]> Thu, 20 Mar 2025 08:28:32 +0000
Newsgroups gmane.comp.security.shorewall
Message-ID <ZR1P278MB1222831953954C70D8B5F43897D82@ZR1P278MB1222.CHEP278.PROD.OUTLOOK.COM>
Thanks Matt.

Yes - if I do a shorewall clear, it's possible to access the host from insi=
de the docker container. The
default docker iptables config seems to support this. However, when I enabl=
e shorewall (with docker
support), it's not possible.

It really seems like some interaction between the docker iptables functiona=
lity and the shorewall
iptables functionality is causing the problem and more specifically, on the=
 return path from the service
running on the host to the docker container.

It could be something of an edge case as mostly the point of having contain=
ers is to have (some) =

isolation from the host but we think it prob should be possible to eg acces=
s stuff from inside the =

containers which is accessible from anywhere on the internet.

Thanks for any insights.

BR,
Sean.

__________________________________
Sean Murphy
Senior Platform Engineer
[email protected]
T +41 44=A0 289-84-22
www.datahouse.ch
Linkedin=A0| YouTube
__________________________________


________________________________________
From:=A0Matt Darfeuille <[email protected]>
Sent:=A0Wednesday, March 19, 2025 8:19 PM
To:[email protected] <[email protected]=
rge.net>
Subject:=A0Re: [Shorewall-users] Problems accessing host from docker contai=
ner running on host
=A0
[You don't often get email from [email protected]. Learn why this is impor=
tant at https://aka.ms/LearnAboutSenderIdentification=A0]

On 3/19/25 10:49, Sean Murphy via Shorewall-users wrote:
> Hi all,,
>
> We have been (ab)using shorewall for some years now and we're v happy wit=
h it -
> thanks everyone and Tom in particular for such a great tool.
>
> We have been using it to manage security for a set of VMs running applica=
tions
> with docker-compose. Almost all of our hosts have a single external netwo=
rk
> interface; this is perhaps not the use case for which shorewall was desig=
ned
> but it has been working for us so far.
>
> We now have a scenario which is proving more difficult: we want to access=
 a
> service running on a host from within a container.
>
> We have tried the most open configuration possible - a policy with all:all
> ACCEPT and no rules; it seems the service is accessible from anywhere exc=
ept
> inside the docker container.
>
> Accessing the service from inside the container results in timeouts, so p=
resumably
> the packets are being dropped somewhere. We tried ping, ssh (on standard =
ports)
> and an http service running on a high port number.
>
> Zone configuration:
> root@dhit-disposable01:/etc/shorewall# cat zones
> #########################################################################=
######
> #ZONE=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 TYPE=A0=A0=A0=A0=A0 OPTIONS=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 IN=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OUT
> #=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OP=
TIONS=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OPTIONS
> fw=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 firewall
> net=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 ipv4
> dock=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 ipv4
>
> Interface configuration:
> root@dhit-disposable01:/etc/shorewall# cat interfaces
> #########################################################################=
######
> ?FORMAT 2
> #########################################################################=
######
> #ZONE=A0=A0 INTERFACE=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 OPT=
IONS
> net=A0=A0=A0=A0 eth=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0 physical=3Deth+,dhcp,nosmurfs
> net=A0=A0=A0=A0 en=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0 physical=3Den+,dhcp,nosmurfs
> dock=A0=A0=A0 docker0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0 physical=3Ddocker+,routeback=3D1
> dock=A0=A0=A0 br=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0 physical=3Dbr-+,routeback=3D1
>
> Policy configuration:
> root@dhit-disposable01:/etc/shorewall# cat policy
> #SOURCE=A0=A0=A0=A0=A0=A0=A0 DEST=A0=A0=A0=A0=A0=A0=A0 POLICY=A0=A0=A0=A0=
=A0 LOGLEVEL=A0=A0=A0 LIMIT
> all=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 all=A0=A0=A0=A0=A0=A0=A0=A0 ACCEPT
>
> Rules configuration:
> root@dhit-disposable01:/etc/shorewall# cat rules
> #ACTION=A0=A0=A0=A0=A0 SOURCE=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0 DEST=A0=A0=A0=A0=A0=A0 PROTO=A0=A0=A0=A0=A0 DPORT
> # No rules
>
> Docker configuration as per shorewall.conf
> root@dhit-disposable01:/etc/shorewall# grep -i docker shorewall.conf
> # Default shorewall config, except for DOCKER=3DYes (and this comment).
> DOCKER=3DYes
> DOCKER_BRIDGE=3Ddocker0
>
> I did shorewall compile, safe-reload and then restarted the docker deamon=
 but
> the packets still seem to be being dropped. I tried iptables-tracer [1] t=
o get some
> info on where they disappear and it seems packets are being dropped on the
> return path.

If you do a `shorewall clear`, does it work at all?


Note that the project is unmaintained.

--
Matt Darfeuille <[email protected]>
Unmaintained project, no more releases or bug fixes
Community: https://sourceforge.net/p/shorewall/mailman/message/37107049/


_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users