【问题标题】:iptables DROP on port only for remote connectionsiptables DROP on port 仅用于远程连接
【发布时间】:2019-06-19 07:25:24
【问题描述】:

我的虚拟机上运行了几个 docker 容器。

其中一个使用 HTTP 服务器 (django/python) 公开 8000 端口。另一方面,安装了nginx,它监听80端口和代理传递到8000:

proxy_pass http://127.0.0.1:8000

完美运行。但是如果我直接从浏览器连接到 8000 端口,比如:

http://example.com:8000/

它返回来自内部 docker 处理程序的响应。

如何关闭那个 8000 端口而不伤害一切?

我尝试使用iptables 实用程序来执行此操作,但似乎 docker 创建了很多自己的规则,我不知道是否会在不破坏这些 docker 规则的情况下创建一个正常的规则:

Chain INPUT (policy ACCEPT)
target     prot opt source               destination         

Chain FORWARD (policy DROP)
target     prot opt source               destination         
DOCKER-USER  all  --  anywhere             anywhere            
DOCKER-ISOLATION-STAGE-1  all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED
DOCKER     all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED
DOCKER     all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere            

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination         

Chain DOCKER (2 references)
target     prot opt source               destination         

Chain DOCKER-ISOLATION-STAGE-1 (1 references)
target     prot opt source               destination         
DOCKER-ISOLATION-STAGE-2  all  --  anywhere             anywhere            
DOCKER-ISOLATION-STAGE-2  all  --  anywhere             anywhere            
RETURN     all  --  anywhere             anywhere            

Chain DOCKER-ISOLATION-STAGE-2 (2 references)
target     prot opt source               destination         
DROP       all  --  anywhere             anywhere            
DROP       all  --  anywhere             anywhere            
RETURN     all  --  anywhere             anywhere            

Chain DOCKER-USER (1 references)
target     prot opt source               destination         
RETURN     all  --  anywhere             anywhere            

计划做:

iptables -A INPUT -p tcp --dport 8000 -j REJECT

可以吗?

【问题讨论】:

标签: linux docker nginx iptables


【解决方案1】:

只有使用 docker run -p 选项(或 Docker Compose ports: 选项)明确发布的端口才能从其他主机访问。您不需要这个选项只是为了在容器之间进行通信;位于同一 Docker 内部网络上的两个容器可以使用彼此的容器名称作为主机名和容器内部端口进行通信,而无需任何“发布”或“公开”选项。

简而言之,从您的后端容器中删除 -p 选项,它将无法从主机外直接访问。您无需手动更改iptables 规则。

【讨论】:

    猜你喜欢
    • 2015-09-29
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2023-03-22
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多