Re: Problems accessing host from docker container running on host

Sean Murphy via Shorewall-users <[email protected]> Wed, 2 Apr 2025 08:34:47 +0000
Newsgroups gmane.comp.security.shorewall
Message-ID <ZR1P278MB12220C7588E162A7474CBE9697AF2@ZR1P278MB1222.CHEP278.PROD.OUTLOOK.COM>
Thanks=A0all for providing some inputs here.

We've found that there have been some changes to docker iptables rule manag=
ement which have
impacted us - see here: https://github.com/moby/moby/commit/c9fdeaf70e71506=
487244df4f6d586eb937981f4

At this point, we're not sure if we can find a workable solution for our co=
ntext which combines shorewall and =

docker - I will update here if we do.

BR,
Sean.

__________________________________
Sean Murphy
Senior Platform Engineer
[email protected]
T +41 44=A0 289-84-22
www.datahouse.ch
Linkedin=A0| YouTube
__________________________________


________________________________________
From:=A0Winston Sorfleet <[email protected]>
Sent:=A0Friday, March 21, 2025 11:53 PM
To:[email protected] <[email protected]=
rge.net>
Subject:=A0Re: [Shorewall-users] Problems accessing host from docker contai=
ner running on host
=A0
[You don't often get email from [email protected]. Learn why this is important=
 at https://aka.ms/LearnAboutSenderIdentification=A0]

Vieri is right, I did miss the "all all ACCEPT" with the message thread
truncation.=A0 Still... like Roger I would be a little more assured if
Sean put in an explicit "dock fw ACCEPT" and "fw dock ACCEPT" just for
testing.=A0 Particularly given the potential complication of a bridge
interface.=A0 I am also sort of wondering if packets might be going out
the "docker0" interface and back via "br" or vice-versa, which certainly
a tcpdump -i any would show (I'd suggest putting some constraints around
src, dst, and port or proto if you want to avoid a deluge of output).

Also, you can try the "diff" thing also with "ip route show", and with
"shorewall show routing", with shorewall running/clear, might give some
clues.

On 2025-03-21 10:42, Roger Hayter wrote:
> ISTR =91all=92 doesn=92t include the firewall unless you explicitly state=
 it (or use =91all+=92 but I=92m less sure of this).=A0 So doesn=92t there =
need to be a policy of =91dock=92 to $FW ACCEPT?
>
>
> --
>
> Roger Hayter
>
>
>> On 21 Mar 2025, at 13:08, Vieri Di Paola <[email protected]> wrote:
>>
>>
>>
>> On Fri, Mar 21, 2025, 13:16 Winston Sorfleet <[email protected]> wrote:
>> Well, it would seem to me that's the problem - your VM is in the Docker
>> zone, and the host you want to access is in the Fw zone.
>>
>> But OP has 'all all ACCEPT' as policy.
>> Try setting to 'all all ACCEPT INFO' and confirm in logs that you see th=
e traffic you need.
>> If outgoing ok but no reply, you might want to check routing tables.
>> Are the replies routed back as expected to the right interface?
>>
>> _______________________________________________
>> Shorewall-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>
>
>
>
>
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>


_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users