Don't forward any docker traffic
Access to the 23080 local port will be done by applying the INPUT rules, which pass through nixos-fw. Reviewed-by: Aleix Boné <abonerib@bsc.es>
This commit is contained in:
		
							parent
							
								
									624e4b8481
								
							
						
					
					
						commit
						fe016f3443
					
				| @ -99,10 +99,9 @@ | ||||
| 
 | ||||
|   # DOCKER* chains are useless, override at FORWARD and nixos-fw | ||||
|   networking.firewall.extraCommands = '' | ||||
|     # Allow docker to use our proxy | ||||
|     iptables -I FORWARD 1 -p tcp -i docker0 -d hut --dport 23080 -j nixos-fw-accept | ||||
|     # Block anything else coming from docker | ||||
|     iptables -I FORWARD 2 -p all -i docker0 -j nixos-fw-log-refuse | ||||
|     # Don't forward any traffic from docker | ||||
|     iptables -I FORWARD 1 -p all -i docker0 -j nixos-fw-log-refuse | ||||
| 
 | ||||
|     # Allow incoming traffic from docker to 23080 | ||||
|     iptables -A nixos-fw -p tcp -i docker0 -d hut --dport 23080 -j ACCEPT | ||||
|   ''; | ||||
|  | ||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user