-
Notifications
You must be signed in to change notification settings - Fork 18.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Getting WARNING: bridge-nf-call-iptables is disabled with overlay storage driver #24809
Comments
This is not related to anything with storage, and is just because either Closing since this is not a real issue. |
I had this issue : I run my Docker on CentOS with SELinux enforcing and FirewallD on
ref: http://wiki.libvirt.org/page/Net.bridge.bridge-nf-call_and_sysctl.conf PS: I also have those lines who seems having action on this warning too
|
I solve this problem by execting two commands: |
@frankruizhi is right, using the command $sudo sysctl net.bridge.bridge-nf-call-iptables=1
$sudo sysctl net.bridge.bridge-nf-call-ip6tables=1 |
@frankruizhi is right, however this is not permanent. If you reboot, the change will lost. When you type
In the end, run |
Source: https://docs.oracle.com/en/operating-systems/oracle-linux/docker/issue-iptables-warning.html This is expected behavior. These settings control whether packets traversing a network bridge are processed by iptables rules on the host system. Typically, enabling these options is not desirable as this can cause guest container traffic to be blocked by iptables rules that are intended for the host. This could cause unpredictable behavior for containers that do not expect traffic to be firewalled at the host level. If you accept and understand the implications of enabling these options or you have no iptables rules set on the host, you can enable these options to remove the warning messages. |
Hi!
where could I find the
Thanks! |
@matbillo The docker server and that directory are obviously not on the Windows file system but inside a WSL distribution as you can see from the command output you posted. The distro is called docker-desktop. The way i reached that config file was by opening command prompt and using Helpful screenshot if you prefer visuals: |
Then what is the correct way to suppress the warnings if one does not want to enable those two options? |
[root@dcosa12 ~]# docker info
Containers: 9
Running: 0
Paused: 0
Stopped: 9
Images: 3
Server Version: 1.12.0-rc4
Storage Driver: overlay
Backing Filesystem: xfs
Logging Driver: json-file
Cgroup Driver: cgroupfs
Plugins:
Volume: local
Network: host bridge null overlay
Swarm: inactive
Runtimes: runc
Default Runtime: runc
Security Options: seccomp
Kernel Version: 3.10.0-327.10.1.el7.x86_64
Operating System: CentOS Linux 7 (Core)
OSType: linux
Architecture: x86_64
CPUs: 6
Total Memory: 11.43 GiB
Name: dcosa12
ID: XON7:NI34:SW5V:YACY:S7UI:4RJT:YWAJ:PG7W:XG4N:T7NC:AGLK:UQJR
Docker Root Dir: /var/lib/docker
Debug Mode (client): false
Debug Mode (server): false
Registry: https://index.docker.io/v1/
WARNING: bridge-nf-call-iptables is disabled
WARNING: bridge-nf-call-ip6tables is disabled
Insecure Registries:
127.0.0.0/8
[root@dcosa12 ~]# uname -a
Linux dcosa12 3.10.0-327.10.1.el7.x86_64 #1 SMP Tue Feb 16 17:03:50 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
[root@dcosa12 etc]# more centos-release
CentOS Linux release 7.2.1511 (Core)
[root@dcosa12 etc]#
The text was updated successfully, but these errors were encountered: