Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    TCP:R blocks with open rules

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 3 Posters 1.7k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rml_52
      last edited by

      It appears that the docker is internally NATing the traffic as the VMs IP but only part of it. The reset is not being masqueraded in iptables. I am trying to find documents about setting up docker masqurade in iptables to see if this helps.

      1 Reply Last reply Reply Quote 0
      • R Offline
        rml_52 @KOM
        last edited by rml_52

        @KOM So all the references I could find say that that behavior is exactly what docker does. it creates a network not in use, creates a bridge, and masquerades all traffic out the eth0 port.

        That all seems setup correct but for some reason TCP:R traffic is not being masked.
        I tried editing the iptables on the server but logs still are happening...

        If anyone is an iptables master and wants to see let me know.
        I tried to post pics but the site keeps blocking me as spam

        1 Reply Last reply Reply Quote 1
        • KOMK Offline
          KOM
          last edited by

          If everything is working correctly and you're just tired of the log spam, you could create your own custom rule to block that traffic and set it to not log.

          R 1 Reply Last reply Reply Quote 0
          • R Offline
            rml_52 @KOM
            last edited by

            @KOM I believe everything is working for the apps needed traffic but the state table is filling up and nothing is closing because the reset is blocked.
            I created a rule to allow the traffic but it's not working because its not a routed network on the interface and I dont know how to fix that...
            Granted the system should be bridging and masking all traffic out eth0 as 192.168.5.2 and not 172.17.0.2 so I am in other forums trying to fix that but also dont want issues from reset blocks and state table. And if they cant fix it on the server then i want the firewall to allow it

            1 Reply Last reply Reply Quote 0
            • M Offline
              Moh
              last edited by

              Hi Kom,

              Have this been resolved, im sitting with the same issue.

              R 1 Reply Last reply Reply Quote 0
              • R Offline
                rml_52 @Moh
                last edited by

                @Moh not on my end... but I gave up trying

                M 1 Reply Last reply Reply Quote 0
                • M Offline
                  Moh @rml_52
                  last edited by

                  @rml_52 said in TCP:R blocks with open rules:

                  not on my end... but I gave up trying

                  Do you still run docker on that port? i assume you ran Storj?

                  R 1 Reply Last reply Reply Quote 1
                  • R Offline
                    rml_52 @Moh
                    last edited by

                    @Moh yes. It seems that docker is not being masquerading properly and sending traffic using the 172 private IP instead of the the configured IP for eth0 and the pfsense firewall doesnt know how to handle it

                    M 1 Reply Last reply Reply Quote 0
                    • KOMK Offline
                      KOM
                      last edited by

                      @Moh I bumped your rep by one. I think you have to have at least 5 or your posts get filtered a lot harder.

                      1 Reply Last reply Reply Quote 1
                      • M Offline
                        Moh @rml_52
                        last edited by

                        @rml_52 I have fixed my issue today, i have switch my storagenode docker from "bridge" network to use the "host" network. Then allowed the rules on Linux to let traffic through for the port.

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.