YIKES!!
Docker is exposing local ports to my WAN interface.
Can anyone offer any tips (besides virtualization) . Running on an N5105 aliexpress wannabe pfsens box
~$ sudo iptables -t nat -L -n
Chain PREROUTING (policy ACCEPT)
target prot opt source destination
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9120 to:10.10.0.1:443
DOCKER all -- 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type LOCAL
Chain INPUT (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
DOCKER all -- 0.0.0.0/0 !127.0.0.0/8 ADDRTYPE match dst-type LOCAL
Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
MASQUERADE all -- 172.17.0.0/16 0.0.0.0/0
MASQUERADE all -- 172.30.32.0/23 0.0.0.0/0
MASQUERADE all -- 0.0.0.0/0 0.0.0.0/0
MASQUERADE tcp -- 172.30.32.6 172.30.32.6 tcp dpt:80
MASQUERADE tcp -- 172.30.33.1 172.30.33.1 tcp dpt:1627
MASQUERADE tcp -- 172.30.33.3 172.30.33.3 tcp dpt:8884
MASQUERADE tcp -- 172.30.33.3 172.30.33.3 tcp dpt:8883
MASQUERADE tcp -- 172.30.33.3 172.30.33.3 tcp dpt:1884
MASQUERADE tcp -- 172.30.33.3 172.30.33.3 tcp dpt:1883
MASQUERADE tcp -- 172.30.33.4 172.30.33.4 tcp dpt:443
MASQUERADE tcp -- 172.30.33.6 172.30.33.6 tcp dpt:8485
MASQUERADE tcp -- 172.30.33.0 172.30.33.0 tcp dpt:443
MASQUERADE tcp -- 172.30.33.1 172.30.33.1 tcp dpt:8485
MASQUERADE tcp -- 172.30.33.1 172.30.33.1 tcp dpt:8099
MASQUERADE tcp -- 172.30.33.5 172.30.33.5 tcp dpt:1627
Chain DOCKER (2 references)
target prot opt source destination
RETURN all -- 0.0.0.0/0 0.0.0.0/0
RETURN all -- 0.0.0.0/0 0.0.0.0/0
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:4357 to:172.30.32.6:80
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:443 to:172.30.33.0:443
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8485 to:172.30.33.1:8485
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8099 to:172.30.33.1:8099
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8884 to:172.30.33.3:8884
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8883 to:172.30.33.3:8883
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:1627 to:172.30.33.5:1627
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:1884 to:172.30.33.3:1884
DNAT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:1883 to:172.30.33.3:1883
Chain DOCKER-USER (0 references)
target prot opt source destination
Chain INPUT (policy ACCEPT)
target prot opt source destination
DROP all -- 0.0.0.0/0 0.0.0.0/0 match-set crowdsec-blacklists src
ACCEPT all -- 127.0.0.0/8 127.0.0.0/8
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state ESTABLISHED
REJECT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:33434:33523 reject-with icmp-port-unreachable
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9443
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:67:68
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8123
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
DROP all -- 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy ACCEPT)
target prot opt source destination
DOCKER-USER all -- 0.0.0.0/0 0.0.0.0/0
DOCKER-ISOLATION-STAGE-1 all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
DOCKER all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
DOCKER all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 172.30.32.1 tcp dpt:9120
ACCEPT tcp -- 0.0.0.0/0 172.30.32.1 tcp dpt:8444
ACCEPT tcp -- 0.0.0.0/0 10.10.0.1 tcp dpt:443
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
DROP all -- 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain DOCKER (2 references)
target prot opt source destination
ACCEPT tcp -- 0.0.0.0/0 172.30.32.6 tcp dpt:80
ACCEPT tcp -- 0.0.0.0/0 172.30.33.0 tcp dpt:443
ACCEPT tcp -- 0.0.0.0/0 172.30.33.1 tcp dpt:8485
ACCEPT tcp -- 0.0.0.0/0 172.30.33.1 tcp dpt:8099
ACCEPT tcp -- 0.0.0.0/0 172.30.33.3 tcp dpt:8884
ACCEPT tcp -- 0.0.0.0/0 172.30.33.3 tcp dpt:8883
ACCEPT tcp -- 0.0.0.0/0 172.30.33.5 tcp dpt:1627
ACCEPT tcp -- 0.0.0.0/0 172.30.33.3 tcp dpt:1884
ACCEPT tcp -- 0.0.0.0/0 172.30.33.3 tcp dpt:1883
Chain DOCKER-ISOLATION-STAGE-1 (1 references)
target prot opt source destination
DOCKER-ISOLATION-STAGE-2 all -- 0.0.0.0/0 0.0.0.0/0
DOCKER-ISOLATION-STAGE-2 all -- 0.0.0.0/0 0.0.0.0/0
RETURN all -- 0.0.0.0/0 0.0.0.0/0
Chain DOCKER-ISOLATION-STAGE-2 (2 references)
target prot opt source destination
DROP all -- 0.0.0.0/0 0.0.0.0/0
DROP all -- 0.0.0.0/0 0.0.0.0/0
RETURN all -- 0.0.0.0/0 0.0.0.0/0
Chain DOCKER-USER (1 references)
target prot opt source destination
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
RETURN all -- 0.0.0.0/0 0.0.0.0/0