Skip to content
Discussion options

You must be logged in to vote

Those scans pin it down, and they also show I had the UFW part of my first reply backwards. It is UFW, just not on the path you allowed.

With the container stopped, a SYN to port 80 reaches the host itself, UFW's 80/tcp allow lets it into INPUT, nothing listens there, and the kernel answers with a RST: closed. With the container running, podman rewrites that SYN to the container's address before routing, so it no longer goes to INPUT at all. It goes through FORWARD, and UFW's default for forwarded traffic is deny (routed) (DEFAULT_FORWARD_POLICY="DROP" in /etc/default/ufw), which drops it silently: filtered. Your ufw allow rules only apply to INPUT, so they never see it. From the server i…

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
5 replies
@FishyBusinessYT
Comment options

@jmrplens
Comment options

Answer selected by FishyBusinessYT
@FishyBusinessYT
Comment options

@jmrplens
Comment options

@FishyBusinessYT
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants