UFW not blocking incoming traffic The 2019 Stack Overflow Developer Survey Results Are In Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern) Come Celebrate our 10 Year Anniversary!Rate limiting with UFW: setting limitsUFW/IPTables: after setting default outgoing deny, and port 80 outgoing allow, curl still doesn't workUFW/IPTables: how to securely allow authenticated git access with githubMaking a server “read only” except for me (what the inbound/outbound rules mean)UFW not working on Debian while ufw status looks goodUFW blocks permitted portsAWS instance has port open in security group, ufw rule, but nmap says it's closedOpenVPN can connect but no internet unless UFW is disabledHow to protect VPS by UFW firewall properly?ufw deny network rule not working
Button changing its text & action. Good or terrible?
how can a perfect fourth interval be considered either consonant or dissonant?
How to make Illustrator type tool selection automatically adapt with text length
Is every episode of "Where are my Pants?" identical?
For what reasons would an animal species NOT cross a *horizontal* land bridge?
Circular reasoning in L'Hopital's rule
ELI5: Why do they say that Israel would have been the fourth country to land a spacecraft on the Moon and why do they call it low cost?
How many cones with angle theta can I pack into the unit sphere?
Can a flute soloist sit?
Simulating Exploding Dice
Is 'stolen' appropriate word?
Am I ethically obligated to go into work on an off day if the reason is sudden?
Did the new image of black hole confirm the general theory of relativity?
Identify 80s or 90s comics with ripped creatures (not dwarves)
Sub-subscripts in strings cause different spacings than subscripts
Can withdrawing asylum be illegal?
Can I visit the Trinity College (Cambridge) library and see some of their rare books
Why doesn't shell automatically fix "useless use of cat"?
Single author papers against my advisor's will?
Does Parliament need to approve the new Brexit delay to 31 October 2019?
Student Loan from years ago pops up and is taking my salary
My body leaves; my core can stay
Accepted by European university, rejected by all American ones I applied to? Possible reasons?
Windows 10: How to Lock (not sleep) laptop on lid close?
UFW not blocking incoming traffic
The 2019 Stack Overflow Developer Survey Results Are In
Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)
Come Celebrate our 10 Year Anniversary!Rate limiting with UFW: setting limitsUFW/IPTables: after setting default outgoing deny, and port 80 outgoing allow, curl still doesn't workUFW/IPTables: how to securely allow authenticated git access with githubMaking a server “read only” except for me (what the inbound/outbound rules mean)UFW not working on Debian while ufw status looks goodUFW blocks permitted portsAWS instance has port open in security group, ufw rule, but nmap says it's closedOpenVPN can connect but no internet unless UFW is disabledHow to protect VPS by UFW firewall properly?ufw deny network rule not working
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I have a Debian 9 Server running UFW, and i'd like to block all incoming requests except on port 2122 (SSH), and 80/443 (For HTTP(s)).
I ran the following commands :
ufw reset
ufw default deny incoming
ufw default allow outgoing
ufw allow incoming 2122/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
Which compiles to :
ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), deny (routed)
New profiles: skip
To Action From
-- ------ ----
2122/tcp ALLOW IN Anywhere
80/tcp ALLOW IN Anywhere
443/tcp ALLOW IN Anywhere
2122/tcp (v6) ALLOW IN Anywhere (v6)
80/tcp (v6) ALLOW IN Anywhere (v6)
443/tcp (v6) ALLOW IN Anywhere (v6)
Seems like everything is fine, at least to me. But, when i run a docker container, on port 2424 (or, really, any other port), i can still access http://domain.tld:2424, despite the firewall.
I tried rebooting, restarting iptables, ... No dice.
Any suggestion ? Thanks a lot !
debian firewall ufw
New contributor
add a comment |
I have a Debian 9 Server running UFW, and i'd like to block all incoming requests except on port 2122 (SSH), and 80/443 (For HTTP(s)).
I ran the following commands :
ufw reset
ufw default deny incoming
ufw default allow outgoing
ufw allow incoming 2122/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
Which compiles to :
ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), deny (routed)
New profiles: skip
To Action From
-- ------ ----
2122/tcp ALLOW IN Anywhere
80/tcp ALLOW IN Anywhere
443/tcp ALLOW IN Anywhere
2122/tcp (v6) ALLOW IN Anywhere (v6)
80/tcp (v6) ALLOW IN Anywhere (v6)
443/tcp (v6) ALLOW IN Anywhere (v6)
Seems like everything is fine, at least to me. But, when i run a docker container, on port 2424 (or, really, any other port), i can still access http://domain.tld:2424, despite the firewall.
I tried rebooting, restarting iptables, ... No dice.
Any suggestion ? Thanks a lot !
debian firewall ufw
New contributor
add a comment |
I have a Debian 9 Server running UFW, and i'd like to block all incoming requests except on port 2122 (SSH), and 80/443 (For HTTP(s)).
I ran the following commands :
ufw reset
ufw default deny incoming
ufw default allow outgoing
ufw allow incoming 2122/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
Which compiles to :
ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), deny (routed)
New profiles: skip
To Action From
-- ------ ----
2122/tcp ALLOW IN Anywhere
80/tcp ALLOW IN Anywhere
443/tcp ALLOW IN Anywhere
2122/tcp (v6) ALLOW IN Anywhere (v6)
80/tcp (v6) ALLOW IN Anywhere (v6)
443/tcp (v6) ALLOW IN Anywhere (v6)
Seems like everything is fine, at least to me. But, when i run a docker container, on port 2424 (or, really, any other port), i can still access http://domain.tld:2424, despite the firewall.
I tried rebooting, restarting iptables, ... No dice.
Any suggestion ? Thanks a lot !
debian firewall ufw
New contributor
I have a Debian 9 Server running UFW, and i'd like to block all incoming requests except on port 2122 (SSH), and 80/443 (For HTTP(s)).
I ran the following commands :
ufw reset
ufw default deny incoming
ufw default allow outgoing
ufw allow incoming 2122/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
Which compiles to :
ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), deny (routed)
New profiles: skip
To Action From
-- ------ ----
2122/tcp ALLOW IN Anywhere
80/tcp ALLOW IN Anywhere
443/tcp ALLOW IN Anywhere
2122/tcp (v6) ALLOW IN Anywhere (v6)
80/tcp (v6) ALLOW IN Anywhere (v6)
443/tcp (v6) ALLOW IN Anywhere (v6)
Seems like everything is fine, at least to me. But, when i run a docker container, on port 2424 (or, really, any other port), i can still access http://domain.tld:2424, despite the firewall.
I tried rebooting, restarting iptables, ... No dice.
Any suggestion ? Thanks a lot !
debian firewall ufw
debian firewall ufw
New contributor
New contributor
New contributor
asked Apr 8 at 11:47
RogueRogue
1133
1133
New contributor
New contributor
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
Docker opens ports in the firewall itself, for any ports that are EXPOSEd by the running containers. These do not show up in ufw
output, but can be viewed in iptables
.
You should:
- Ensure that only ports that need to be accessible to the Internet are EXPOSEd.
- Use docker-compose to orchestrate the creation and running of multiple related containers. They can talk to each other without having to expose ports.
It makes a lot of sense. Didn't know Docker was interacting with iptables ! Works like a charm when usingexpose
instated ofport
s. Thanks !
– Rogue
Apr 8 at 18:19
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Rogue is a new contributor. Be nice, and check out our Code of Conduct.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962012%2fufw-not-blocking-incoming-traffic%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Docker opens ports in the firewall itself, for any ports that are EXPOSEd by the running containers. These do not show up in ufw
output, but can be viewed in iptables
.
You should:
- Ensure that only ports that need to be accessible to the Internet are EXPOSEd.
- Use docker-compose to orchestrate the creation and running of multiple related containers. They can talk to each other without having to expose ports.
It makes a lot of sense. Didn't know Docker was interacting with iptables ! Works like a charm when usingexpose
instated ofport
s. Thanks !
– Rogue
Apr 8 at 18:19
add a comment |
Docker opens ports in the firewall itself, for any ports that are EXPOSEd by the running containers. These do not show up in ufw
output, but can be viewed in iptables
.
You should:
- Ensure that only ports that need to be accessible to the Internet are EXPOSEd.
- Use docker-compose to orchestrate the creation and running of multiple related containers. They can talk to each other without having to expose ports.
It makes a lot of sense. Didn't know Docker was interacting with iptables ! Works like a charm when usingexpose
instated ofport
s. Thanks !
– Rogue
Apr 8 at 18:19
add a comment |
Docker opens ports in the firewall itself, for any ports that are EXPOSEd by the running containers. These do not show up in ufw
output, but can be viewed in iptables
.
You should:
- Ensure that only ports that need to be accessible to the Internet are EXPOSEd.
- Use docker-compose to orchestrate the creation and running of multiple related containers. They can talk to each other without having to expose ports.
Docker opens ports in the firewall itself, for any ports that are EXPOSEd by the running containers. These do not show up in ufw
output, but can be viewed in iptables
.
You should:
- Ensure that only ports that need to be accessible to the Internet are EXPOSEd.
- Use docker-compose to orchestrate the creation and running of multiple related containers. They can talk to each other without having to expose ports.
answered Apr 8 at 13:21
Michael Hampton♦Michael Hampton
175k27320648
175k27320648
It makes a lot of sense. Didn't know Docker was interacting with iptables ! Works like a charm when usingexpose
instated ofport
s. Thanks !
– Rogue
Apr 8 at 18:19
add a comment |
It makes a lot of sense. Didn't know Docker was interacting with iptables ! Works like a charm when usingexpose
instated ofport
s. Thanks !
– Rogue
Apr 8 at 18:19
It makes a lot of sense. Didn't know Docker was interacting with iptables ! Works like a charm when using
expose
instated of port
s. Thanks !– Rogue
Apr 8 at 18:19
It makes a lot of sense. Didn't know Docker was interacting with iptables ! Works like a charm when using
expose
instated of port
s. Thanks !– Rogue
Apr 8 at 18:19
add a comment |
Rogue is a new contributor. Be nice, and check out our Code of Conduct.
Rogue is a new contributor. Be nice, and check out our Code of Conduct.
Rogue is a new contributor. Be nice, and check out our Code of Conduct.
Rogue is a new contributor. Be nice, and check out our Code of Conduct.
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962012%2fufw-not-blocking-incoming-traffic%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown