Hello,
I have an issue, I want to use embeded firewall with one public IP, and the container can't access to internet.
Thanks.
I have an issue, I want to use embeded firewall with one public IP, and the container can't access to internet.
Code:
enable: 1
policy_in: ACCEPT
[RULES]
IN SSH(ACCEPT) -log nolog
IN ACCEPT -p tcp -dport 8006 -log nolog
root@opale:~# cat /etc/pve/firewall/100.fw
[OPTIONS]
policy_in: ACCEPT
enable: 1
[ALIASES]
CT100 192.168.0.100
[RULES]
IN SMTPS(ACCEPT) -log nolog
IN SMTP(ACCEPT) -log nolog
IN IMAPS(ACCEPT) -log nolog
IN IMAP(ACCEPT) -log nolog
IN POP3S(ACCEPT) -log nolog
IN POP3(ACCEPT) -log nolog
IN Web(ACCEPT) -log nolog
IN ACCEPT -dest ct100 -p tcp -dport 22 -sport 22100 -log nolog # SSH
root@opale:~# ip address
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: enp4s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 00:25:90:0e:44:a8 brd ff:ff:ff:ff:ff:ff
inet 91.121.xx.xx/24 brd 91.121.xx.255 scope global dynamic enp4s0
valid_lft 67403sec preferred_lft 67403sec
inet6 fe80::225:90ff:fe0e:44a8/64 scope link
valid_lft forever preferred_lft forever
3: enp5s0: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 00:25:90:0e:44:a9 brd ff:ff:ff:ff:ff:ff
4: vmbr0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 46:b3:c6:08:73:4d brd ff:ff:ff:ff:ff:ff
inet 192.168.0.1/24 brd 192.168.0.255 scope global vmbr0
valid_lft forever preferred_lft forever
inet6 fe80::78bf:37ff:fe4e:6f89/64 scope link
valid_lft forever preferred_lft forever
11: veth100i0@if10: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master fwbr100i0 state UP group default qlen 1000
link/ether fe:f1:f7:e4:4b:e7 brd ff:ff:ff:ff:ff:ff link-netnsid 0
12: fwbr100i0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether d2:f9:b3:32:6f:86 brd ff:ff:ff:ff:ff:ff
13: fwpr100p0@fwln100i0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master vmbr0 state UP group default qlen 1000
link/ether 46:b3:c6:08:73:4d brd ff:ff:ff:ff:ff:ff
14: fwln100i0@fwpr100p0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master fwbr100i0 state UP group default qlen 1000
link/ether d2:f9:b3:32:6f:86 brd ff:ff:ff:ff:ff:ff
CONTAINER :
root@agate:~# cat /etc/network/interfaces
auto lo
iface lo inet loopback
auto eth0
iface eth0 inet static
address 192.168.0.100
netmask 255.255.255.0
gateway 192.168.0.1
root@agate:~# traceroute google.fr
google.fr: Temporary failure in name resolution
Cannot handle "host" cmdline arg `google.fr' on position 1 (argc 1)
root@agate:~# traceroute 8.8.8.8
traceroute to 8.8.8.8 (8.8.8.8), 30 hops max, 60 byte packets
1 192.168.0.1 (192.168.0.1) 0.048 ms 0.023 ms 0.022 ms
2 * * *
...
Thanks.
Last edited: