I need the network traffic of a Docker service to pass through VPN, and also to be able to reach other containers outside VPN from that container.
I'm able to get the first requirement working by configuring an OpenConnect service
version: "3.8"
services:
open-connect:
container_name: open-connect
image: open-connect
build:
dockerfile: Docker/OpenConnect.Dockerfile
context: .
privileged: true
environment:
- VPN_PROTOCOL
- VPN_HOST
- VPN_PORT
- VPN_USERNAME
- VPN_PASSWORD
and making the traffic of the other service pass through it via network_mode: container:open-connect
version: "3.8"
services:
vpn-client:
container_name: vpn-client
image: vpn-client
build:
dockerfile: Docker/Busybox.Dockerfile
context: ..
network_mode: container:open-connect
service-a:
hostname: service-a
container_name: service-a
image: service-a
build:
dockerfile: Docker/Busybox.Dockerfile
context: ..
networks:
backend:
service-b:
hostname: service-b
container_name: service-b
image: service-b
build:
dockerfile: Docker/Busybox.Dockerfile
context: ..
networks:
backend:
networks:
backend:
The problem is that only service-a and service-b are able to ping each other.
From vpn-client it is not possible to reach neither service-a or service-b,
similarly in the reverse way.
I cannot combine network-mode and networks in the vpn-client service:
ERROR: 'network_mode' and 'networks' cannot be combined
What else can be done to make the vpn-client, service-a and service-b mutually reachable without being all of them behind VPN network?
Update
VPN Split Tunnelling
Based on some resources I found, the solution seems to be the
configuration of VPN with split-tunnelling instead of full-tunneling.
- https://cybernews.com/what-is-vpn/split-tunneling/
- https://gist.github.com/stefancocora/686bbce938f27ef72649a181e7bd0158
- https://gist.github.com/jagtesh/5531300
So the question becomes: how to configure VPN split-tunnelling in the open-connect service?