goal
The goal is to put a NAT and firewall inside a docker container which acts as gateway for other containers as well as the clients on the LAN. The network configuration and the iptables of the host shall not be changed. If possible the NAT gets its WAN IP address over DHCP.
setup
this is the Dockerfile I'm using:
FROM alpine:latest
COPY start.sh /start.sh
RUN apk add -u iptables --no-cache > /dev/null
CMD ["/start.sh"]
start.sh script for configuring iptables inside the container:
#!/bin/sh
iptables -t nat -A POSTROUTING -o $WAN_IFACE -j MASQUERADE
iptables -A FORWARD -i $WAN_IFACE -o $LAN_IFACE -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i $LAN_IFACE -o $WAN_IFACE -j ACCEPT
while true; do sleep 3600; done
I've tried two complete different approaches so far to run the container:
approach 1 (host network)
docker-compose.yml
version: "2"
services:
nat:
build: ./
container_name: nat
network_mode: host
cap_add:
- NET_ADMIN
environment:
WAN_IFACE: eth2
LAN_IFACE: eth1
other_service:
build: ./other/
container_name: other
network_mode: host
The problem with this setup is, that changes to the network configuration and iptables inside the container also apply to the host computer.
approach 2 (macvlan network)
docker-compose.yml
version: "2"
services:
nat:
build: ./
container_name: nat
networks:
wan_network:
ipv4_address: 10.0.1.100
lan_network:
ipv4_address: 10.0.0.2
cap_add:
- NET_ADMIN
environment:
WAN_IFACE: eth0
LAN_IFACE: eth1
other_service:
build: ./other/
container_name: other
networks:
lan_network:
ipv4_address: 10.0.0.3
networks:
wan_network:
driver: macvlan
driver_opts:
parent: eth2
ipam:
config:
- subnet: 10.0.1.0/24
gateway: 10.0.1.1
ip_range: 10.0.1.0/24
lan_network:
driver: macvlan
driver_opts:
partent: eth1
ipam:
config:
- subnet: 10.0.0.0/24
Because it is not allowed on a macvlan network to assign the IP of the gateway to a container, I can't use the nat container as a NAT for the other services.
I'm pretty new to docker and I'm not sure if what I want to do is possible. I would be really thankful for any help tough.
