Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. If your firewall starts behaving strangely after installing #docker on #opensuse #slowroll, the reason is that firewalld has switched to nft, but docker still uses iptables.

If your firewall starts behaving strangely after installing #docker on #opensuse #slowroll, the reason is that firewalld has switched to nft, but docker still uses iptables.

Scheduled Pinned Locked Moved Uncategorized
dockeropensuseslowroll
7 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ptesarik@infosec.exchangeP This user is from outside of this forum
    ptesarik@infosec.exchangeP This user is from outside of this forum
    ptesarik@infosec.exchange
    wrote last edited by
    #1

    If your firewall starts behaving strangely after installing #docker on #opensuse #slowroll, the reason is that firewalld has switched to nft, but docker still uses iptables. You may have to install iptables (the CLI tool) to fix the damage.

    ffmancera@mastodon.socialF oleksandr@activitypub.natalenko.nameO liskin@genserver.socialL 3 Replies Last reply
    0
    • ptesarik@infosec.exchangeP ptesarik@infosec.exchange

      If your firewall starts behaving strangely after installing #docker on #opensuse #slowroll, the reason is that firewalld has switched to nft, but docker still uses iptables. You may have to install iptables (the CLI tool) to fix the damage.

      ffmancera@mastodon.socialF This user is from outside of this forum
      ffmancera@mastodon.socialF This user is from outside of this forum
      ffmancera@mastodon.social
      wrote last edited by
      #2

      @ptesarik Shouldn't docker be using iptables-nft by default on openSUSE?

      Or am I missing something?

      ptesarik@infosec.exchangeP 1 Reply Last reply
      0
      • ffmancera@mastodon.socialF ffmancera@mastodon.social

        @ptesarik Shouldn't docker be using iptables-nft by default on openSUSE?

        Or am I missing something?

        ptesarik@infosec.exchangeP This user is from outside of this forum
        ptesarik@infosec.exchangeP This user is from outside of this forum
        ptesarik@infosec.exchange
        wrote last edited by
        #3

        @ffmancera No idea. All I know is that packets were no longer forwarded through my default (NAT) libvirt network, and it took me way too long to find out that docker installation/startup did the equivalent of iptables -P FORWARD DROP. It was not visible anywhere in the output of nft list ruleset.

        ffmancera@mastodon.socialF 1 Reply Last reply
        0
        • ptesarik@infosec.exchangeP ptesarik@infosec.exchange

          @ffmancera No idea. All I know is that packets were no longer forwarded through my default (NAT) libvirt network, and it took me way too long to find out that docker installation/startup did the equivalent of iptables -P FORWARD DROP. It was not visible anywhere in the output of nft list ruleset.

          ffmancera@mastodon.socialF This user is from outside of this forum
          ffmancera@mastodon.socialF This user is from outside of this forum
          ffmancera@mastodon.social
          wrote last edited by
          #4

          @ptesarik oh that is too bad

          1 Reply Last reply
          0
          • ptesarik@infosec.exchangeP ptesarik@infosec.exchange

            If your firewall starts behaving strangely after installing #docker on #opensuse #slowroll, the reason is that firewalld has switched to nft, but docker still uses iptables. You may have to install iptables (the CLI tool) to fix the damage.

            oleksandr@activitypub.natalenko.nameO This user is from outside of this forum
            oleksandr@activitypub.natalenko.nameO This user is from outside of this forum
            oleksandr@activitypub.natalenko.name
            wrote last edited by
            #5

            @ptesarik Too bad docker is still used.

            ptesarik@infosec.exchangeP 1 Reply Last reply
            0
            • ptesarik@infosec.exchangeP ptesarik@infosec.exchange

              If your firewall starts behaving strangely after installing #docker on #opensuse #slowroll, the reason is that firewalld has switched to nft, but docker still uses iptables. You may have to install iptables (the CLI tool) to fix the damage.

              liskin@genserver.socialL This user is from outside of this forum
              liskin@genserver.socialL This user is from outside of this forum
              liskin@genserver.social
              wrote last edited by
              #6
              @ptesarik also I've heard that in this setup docker container ports might be exposed to the internet despite whatever firewalld config because the two interact a bit weird

              better double check, or — I'd recommend this — switch to rootless docker/podman which doesn't touch iptables at all
              1 Reply Last reply
              0
              • oleksandr@activitypub.natalenko.nameO oleksandr@activitypub.natalenko.name

                @ptesarik Too bad docker is still used.

                ptesarik@infosec.exchangeP This user is from outside of this forum
                ptesarik@infosec.exchangeP This user is from outside of this forum
                ptesarik@infosec.exchange
                wrote last edited by
                #7

                @oleksandr Please, yes, go fix cobbler to use a better tool for make test-debian12:
                https://github.com/cobbler/cobbler

                1 Reply Last reply
                1
                0
                • R relay@relay.infosec.exchange shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups