Re: Problems accessing host from docker container running on host
Sean Murphy via Shorewall-users <[email protected]> Wed, 2 Apr 2025 08:34:47 +0000
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <ZR1P278MB12220C7588E162A7474CBE9697AF2@ZR1P278MB1222.CHEP278.PROD.OUTLOOK.COM> |
Thanks=A0all for providing some inputs here. We've found that there have been some changes to docker iptables rule manag= ement which have impacted us - see here: https://github.com/moby/moby/commit/c9fdeaf70e71506= 487244df4f6d586eb937981f4 At this point, we're not sure if we can find a workable solution for our co= ntext which combines shorewall and = docker - I will update here if we do. BR, Sean. __________________________________ Sean Murphy Senior Platform Engineer [email protected] T +41 44=A0 289-84-22 www.datahouse.ch Linkedin=A0| YouTube __________________________________ ________________________________________ From:=A0Winston Sorfleet <[email protected]> Sent:=A0Friday, March 21, 2025 11:53 PM To:[email protected] <[email protected]= rge.net> Subject:=A0Re: [Shorewall-users] Problems accessing host from docker contai= ner running on host =A0 [You don't often get email from [email protected]. Learn why this is important= at https://aka.ms/LearnAboutSenderIdentification=A0] Vieri is right, I did miss the "all all ACCEPT" with the message thread truncation.=A0 Still... like Roger I would be a little more assured if Sean put in an explicit "dock fw ACCEPT" and "fw dock ACCEPT" just for testing.=A0 Particularly given the potential complication of a bridge interface.=A0 I am also sort of wondering if packets might be going out the "docker0" interface and back via "br" or vice-versa, which certainly a tcpdump -i any would show (I'd suggest putting some constraints around src, dst, and port or proto if you want to avoid a deluge of output). Also, you can try the "diff" thing also with "ip route show", and with "shorewall show routing", with shorewall running/clear, might give some clues. On 2025-03-21 10:42, Roger Hayter wrote: > ISTR =91all=92 doesn=92t include the firewall unless you explicitly state= it (or use =91all+=92 but I=92m less sure of this).=A0 So doesn=92t there = need to be a policy of =91dock=92 to $FW ACCEPT? > > > -- > > Roger Hayter > > >> On 21 Mar 2025, at 13:08, Vieri Di Paola <[email protected]> wrote: >> >> >> >> On Fri, Mar 21, 2025, 13:16 Winston Sorfleet <[email protected]> wrote: >> Well, it would seem to me that's the problem - your VM is in the Docker >> zone, and the host you want to access is in the Fw zone. >> >> But OP has 'all all ACCEPT' as policy. >> Try setting to 'all all ACCEPT INFO' and confirm in logs that you see th= e traffic you need. >> If outgoing ok but no reply, you might want to check routing tables. >> Are the replies routed back as expected to the right interface? >> >> _______________________________________________ >> Shorewall-users mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/shorewall-users > > > > > > > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users > _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users