You are not logged in.
Pages: 1
So i have tried a lot of different things
I followed pretty much everyting in nj62EcDv7q9k
https://bbs.archlinux.org/viewtopic.php?id=232710
Also read https://wiki.archlinux.org/index.php/Do … leshooting and tried the ip forwarding part
I read a bunch of stackoverflow threads about daemon.json and changing resolv.conf
Im pretty desperate right now. Please send help. Docker containers only have internet if i run with --net=host.
Maybe some relevant info which i've seen asked about from other threads
Offline
Here are some useful info i've seen been asked for in other threads
ip link:
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: enp0s31f6: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc fq_codel state DOWN mode DEFAULT group default qlen 1000
link/ether 54:ee:75:d9:84:d8 brd ff:ff:ff:ff:ff:ff
3: wlp4s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DORMANT group default qlen 1000
link/ether f8:59:71:79:2c:1e brd ff:ff:ff:ff:ff:ff
4: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN mode DEFAULT group default
link/ether 02:42:73:7a:13:a3 brd ff:ff:ff:ff:ff:ff
25: br-01da2d385ce5: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN mode DEFAULT group default
link/ether 02:42:23:df:3a:75 brd ff:ff:ff:ff:ff:ffiptables -S:
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N DOCKER
-N DOCKER-ISOLATION-STAGE-1
-N DOCKER-ISOLATION-STAGE-2
-N DOCKER-USER
-A FORWARD -j DOCKER-USER
-A FORWARD -j DOCKER-ISOLATION-STAGE-1
-A FORWARD -o br-01da2d385ce5 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-01da2d385ce5 -j DOCKER
-A FORWARD -i br-01da2d385ce5 ! -o br-01da2d385ce5 -j ACCEPT
-A FORWARD -i br-01da2d385ce5 -o br-01da2d385ce5 -j ACCEPT
-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o docker0 -j DOCKER
-A FORWARD -i docker0 ! -o docker0 -j ACCEPT
-A FORWARD -i docker0 -o docker0 -j ACCEPT
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i net0 -o internet0 -j ACCEPT
-A DOCKER-ISOLATION-STAGE-1 -i br-01da2d385ce5 ! -o br-01da2d385ce5 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -j RETURN
-A DOCKER-ISOLATION-STAGE-2 -o br-01da2d385ce5 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -j RETURN
-A DOCKER-USER -j RETURNsysctl -a | grep forward:
net.ipv4.conf.all.bc_forwarding = 0
net.ipv4.conf.all.forwarding = 1
net.ipv4.conf.all.mc_forwarding = 0
net.ipv4.conf.br-01da2d385ce5.bc_forwarding = 0
net.ipv4.conf.br-01da2d385ce5.forwarding = 1
net.ipv4.conf.br-01da2d385ce5.mc_forwarding = 0
net.ipv4.conf.default.bc_forwarding = 0
net.ipv4.conf.default.forwarding = 1
net.ipv4.conf.default.mc_forwarding = 0
net.ipv4.conf.docker0.bc_forwarding = 0
net.ipv4.conf.docker0.forwarding = 1
net.ipv4.conf.docker0.mc_forwarding = 0
net.ipv4.conf.enp0s31f6.bc_forwarding = 0
net.ipv4.conf.enp0s31f6.forwarding = 1
net.ipv4.conf.enp0s31f6.mc_forwarding = 0
net.ipv4.conf.lo.bc_forwarding = 0
net.ipv4.conf.lo.forwarding = 1
net.ipv4.conf.lo.mc_forwarding = 0
net.ipv4.conf.wlp4s0.bc_forwarding = 0
net.ipv4.conf.wlp4s0.forwarding = 1
net.ipv4.conf.wlp4s0.mc_forwarding = 0
sysctl: permission denied on key 'net.ipv4.tcp_fastopen_key'
sysctl: permission denied on key 'net.ipv6.conf.all.stable_secret'
net.ipv6.conf.all.forwarding = 0
net.ipv6.conf.all.mc_forwarding = 0
sysctl: permission denied on key 'net.ipv6.conf.br-01da2d385ce5.stable_secret'
net.ipv6.conf.br-01da2d385ce5.forwarding = 0
net.ipv6.conf.br-01da2d385ce5.mc_forwarding = 0
sysctl: permission denied on key 'net.ipv6.conf.default.stable_secret'
net.ipv6.conf.default.forwarding = 0
net.ipv6.conf.default.mc_forwarding = 0
sysctl: permission denied on key 'net.ipv6.conf.docker0.stable_secret'
net.ipv6.conf.docker0.forwarding = 0
net.ipv6.conf.docker0.mc_forwarding = 0
sysctl: permission denied on key 'net.ipv6.conf.enp0s31f6.stable_secret'
net.ipv6.conf.enp0s31f6.forwarding = 0
net.ipv6.conf.enp0s31f6.mc_forwarding = 0
sysctl: permission denied on key 'net.ipv6.conf.lo.stable_secret'
net.ipv6.conf.lo.forwarding = 0
net.ipv6.conf.lo.mc_forwarding = 0
sysctl: permission denied on key 'net.ipv6.conf.wlp4s0.stable_secret'
net.ipv6.conf.wlp4s0.forwarding = 0
net.ipv6.conf.wlp4s0.mc_forwarding = 0Last edited by kharann (2020-02-06 20:47:06)
Offline
If i run
docker run -it itsthenetwork/alpine-tcpdump
and ping the container i get:
listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes
19:44:45.662811 IP6 :: > ff02::16: HBH ICMP6, multicast listener report v2, 1 group record(s), length 28
19:44:45.663182 ARP, Request who-has 178.31.0.1 tell 8f26d01ade32, length 28
19:44:45.663285 ARP, Reply 178.31.0.1 is-at 02:42:73:7a:13:a3 (oui Unknown), length 28
19:44:45.663292 IP 8f26d01ade32.32947 > 129.241.0.200.53: 51728+ PTR? 6.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa. (90)
19:44:45.663411 IP 8f26d01ade32.32947 > 129.241.0.201.53: 51728+ PTR? 6.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa. (90)
19:44:45.906278 IP6 fe80::a1b8:9061:d2f:422c > ff02::16: HBH ICMP6, multicast listener report v2, 1 group record(s), length 28
19:44:45.907309 IP6 fe80::a1b8:9061:d2f:422c > ip6-allrouters: ICMP6, router solicitation, length 16
19:44:55.669838 IP 8f26d01ade32.45630 > 129.241.0.200.53: 34388+ PTR? 1.0.31.178.in-addr.arpa. (41)
19:45:00.675837 IP 8f26d01ade32.41871 > 129.241.0.200.53: 1838+ PTR? 200.0.241.129.in-addr.arpa. (44)
19:45:00.675980 IP 8f26d01ade32.41871 > 129.241.0.201.53: 1838+ PTR? 200.0.241.129.in-addr.arpa. (44)
19:45:05.679326 IP 8f26d01ade32.52755 > 129.241.0.200.53: 15373+ PTR? 201.0.241.129.in-addr.arpa. (44)
19:45:10.682847 IP 8f26d01ade32.40157 > 129.241.0.200.53: 65499+ PTR? c.2.2.4.f.2.d.0.1.6.0.9.8.b.1.a.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa. (90)From the container. which should tell me that some networking works
Last edited by kharann (2020-02-06 20:47:24)
Offline
docker run -it alpine ip a:
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
38: eth0@if39: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP
link/ether 02:42:b2:1f:00:02 brd ff:ff:ff:ff:ff:ff
inet 178.31.0.2/16 brd 178.31.255.255 scope global eth0
valid_lft forever preferred_lft foreverdocker network inspect bridge:
[
{
"Name": "bridge",
"Id": "967e27c48851dc0bbe9063deca2cd2a2b91d5adc46b5c1c4aa6b5b7eef9bf73e",
"Created": "2020-02-06T20:07:30.237113664+01:00",
"Scope": "local",
"Driver": "bridge",
"EnableIPv6": false,
"IPAM": {
"Driver": "default",
"Options": null,
"Config": [
{
"Subnet": "178.31.0.0/16",
"Gateway": "178.31.0.1"
}
]
},
"Internal": false,
"Attachable": false,
"Ingress": false,
"ConfigFrom": {
"Network": ""
},
"ConfigOnly": false,
"Containers": {},
"Options": {
"com.docker.network.bridge.default_bridge": "true",
"com.docker.network.bridge.enable_icc": "true",
"com.docker.network.bridge.enable_ip_masquerade": "true",
"com.docker.network.bridge.host_binding_ipv4": "0.0.0.0",
"com.docker.network.bridge.name": "docker0",
"com.docker.network.driver.mtu": "1500"
},
"Labels": {}
}
]Last edited by kharann (2020-02-06 20:47:47)
Offline
Stop bumping your thread: https://wiki.archlinux.org/index.php/Co … ct#Bumping
And fix your posts with code tags: https://wiki.archlinux.org/index.php/Co … s_and_code
Offline
Pages: 1