mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-27 11:13:02 +02:00
=== Basic Firewall Container
ifdef::topdoc[:imagesdir: {topdoc}../../test/case/containers/firewall_basic]
==== Description
Verify that an nftables container can be used for IP masquerading and
port forwarding to another container.
....
<--- Docker containers --->
.-------------. .----------------------. .--------..---------------.
| | mgmt |------------| mgmt | | | | fire || | web |
| host | data |------------| ext0 | target | int0 | | wall || eth0 | server |
'-------------'.42 .1'----------------------' '--------''---------------'
\ .1 .2 /
192.168.0.0/24 \ 10.0.0.0/24 /
`-- VETH pair --'
....
The web server container is connected to the target on an internal
network, using a VETH pair, serving HTTP on port 91.
The firewall container sets up a port forward with IP masquerding
to/from `ext0:8080` to 10.0.0.2:91.
Operation is verified using HTTP GET requests for internal port 91 and
external port 8080 to ensure the web page, with a known key phrase, is
only reachable from the public interface `ext0`, on 192.168.0.1:8080.
==== Topology
image::topology.svg[Basic Firewall Container topology, align=center, scaledwidth=75%]
==== Sequence
. Set up topology and attach to target DUT
. Set hostname to 'container-host'
. Create VETH pair for web server container
. Create firewall container from bundled OCI image
. Create web server container from bundled OCI image
. Verify firewall container has started
. Verify web container has started
. Verify connectivity, host can reach target:ext0
. Verify 'web' is NOT reachable on http://container-host.local:91
. Verify 'web' is reachable on http://container-host.local:8080