NAT inside Docker

Viewed 1044

goal

The goal is to put a NAT and firewall inside a docker container which acts as gateway for other containers as well as the clients on the LAN. The network configuration and the iptables of the host shall not be changed. If possible the NAT gets its WAN IP address over DHCP.

target network topology

setup

this is the Dockerfile I'm using:

FROM alpine:latest

COPY start.sh /start.sh
RUN apk add -u iptables --no-cache > /dev/null
CMD ["/start.sh"]

start.sh script for configuring iptables inside the container:

#!/bin/sh

iptables -t nat -A POSTROUTING -o $WAN_IFACE -j MASQUERADE
iptables -A FORWARD -i $WAN_IFACE -o $LAN_IFACE -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i $LAN_IFACE -o $WAN_IFACE -j ACCEPT

while true; do sleep 3600; done

I've tried two complete different approaches so far to run the container:

approach 1 (host network)

docker-compose.yml

version: "2"

services: 
  nat:
    build: ./
    container_name: nat
    network_mode: host
    cap_add:
      - NET_ADMIN
    environment:
      WAN_IFACE: eth2
      LAN_IFACE: eth1
  
  other_service:
    build: ./other/
    container_name: other
    network_mode: host

The problem with this setup is, that changes to the network configuration and iptables inside the container also apply to the host computer.

approach 2 (macvlan network)

docker-compose.yml

version: "2"

services:
  nat:
    build: ./
    container_name: nat
    networks:
      wan_network:
        ipv4_address: 10.0.1.100
      lan_network:
        ipv4_address: 10.0.0.2
    cap_add:
      - NET_ADMIN
    environment:
      WAN_IFACE: eth0
      LAN_IFACE: eth1

  other_service:
    build: ./other/
    container_name: other
    networks:
      lan_network:
        ipv4_address: 10.0.0.3

networks:
  wan_network:
    driver: macvlan
    driver_opts:
      parent: eth2
    ipam:
      config:
        - subnet: 10.0.1.0/24
          gateway: 10.0.1.1
          ip_range: 10.0.1.0/24

  lan_network:
    driver: macvlan
    driver_opts:
      partent: eth1
    ipam:
      config:
        - subnet: 10.0.0.0/24

Because it is not allowed on a macvlan network to assign the IP of the gateway to a container, I can't use the nat container as a NAT for the other services.

I'm pretty new to docker and I'm not sure if what I want to do is possible. I would be really thankful for any help tough.

0 Answers
Related