Files

=== Basic Firewall Container

ifdef::topdoc[:imagesdir: {topdoc}../../test/case/containers/firewall_basic]

==== Description

Verify that an nftables container can be used for IP masquerading and
port forwarding to another container.

....
                                                    <--- Docker containers --->
.-------------.            .----------------------. .--------..---------------.
|      | mgmt |------------| mgmt |        |      | |  fire  ||      |  web   |
| host | data |------------| ext0 | target | int0 | |  wall  || eth0 | server |
'-------------'.42       .1'----------------------' '--------''---------------'
                                              \ .1             .2 /
              192.168.0.0/24                   \   10.0.0.0/24   /
                                                `-- VETH pair --'
....

The web server container is connected to the target on an internal
network, using a VETH pair, serving HTTP on port 91.

The firewall container sets up a port forward with IP masquerding
to/from `ext0:8080` to 10.0.0.2:91.

Operation is verified using HTTP GET requests for internal port 91 and
external port 8080 to ensure the web page, with a known key phrase, is
only reachable from the public interface `ext0`, on 192.168.0.1:8080.

==== Topology

image::topology.svg[Basic Firewall Container topology, align=center, scaledwidth=75%]

==== Sequence

. Set up topology and attach to target DUT
. Set hostname to 'container-host'
. Create VETH pair for web server container
. Create firewall container from bundled OCI image
. Create web server container from bundled OCI image
. Verify firewall container has started
. Verify web container has started
. Verify connectivity, host can reach target:ext0
. Verify 'web' is NOT reachable on http://container-host.local:91
. Verify 'web' is reachable on http://container-host.local:8080