Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

swarm-manager 所在 node 上的任意容器都可以访问 2376 端口 #124

Open
wchaoyi opened this issue May 31, 2017 · 1 comment
Open
Labels

Comments

@wchaoyi
Copy link
Member

wchaoyi commented May 31, 2017

关于 2376 的 default calico rule 没有生效。

@fossilet fossilet added the ready label Jun 23, 2017
@liuxu623
Copy link
Member

liuxu623 commented Sep 5, 2017

iptables_04
iptables的nat表会先于filter表生效,匹配到nat表中的DOCKER chain后就不会匹配filter表中calico的chain了

Chain DOCKER (2 references)
 pkts bytes target     prot opt in     out     source               destination
    8   480 RETURN     all  --  docker0 *       0.0.0.0/0            0.0.0.0/0
    4   240 DNAT       tcp  --  !docker0 *       0.0.0.0/0            0.0.0.0/0            tcp dpt:2376 to:172.17.0.2:2375

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants