{"id":8278,"date":"2020-12-30T02:13:02","date_gmt":"2020-12-30T02:13:02","guid":{"rendered":"http:\/\/localhost:8105\/?p=8278"},"modified":"2021-12-07T15:52:29","modified_gmt":"2021-12-07T15:52:29","slug":"docker-breaks-kvm-bridge-fixed","status":"publish","type":"post","link":"https:\/\/blog.shahada.abubakar.net\/?p=8278","title":{"rendered":"Docker breaks KVM Bridge &#8211; Fixed!"},"content":{"rendered":"<p>\u00a0<\/p>\n<div>I recently enabled docker on my desktop PC running Ubuntu 20.04LTS &#8230; and it ended up breaking Bridged Networking on my VirtManager\/KVM Virtual Machines (NAT still works). It turns out that (1) docker sets up some broad rules in the iptables firewall (2) even directly bridged traffic in KVMs goes through the iptables firewall and (3) the rules set by docker messes up the VM traffic.<\/div>\n<div>\u00a0<\/div>\n<div>After some googling I fixed this with:<\/div>\n<div>\u00a0<\/div>\n<div><span style=\"--en-fontfamily: monospace; font-family: 'Source Code Pro',monospace;\">$ sudo systemctl edit docker.service<\/span><\/div>\n<div>\u00a0<\/div>\n<div><span style=\"--en-fontfamily: monospace; font-family: 'Source Code Pro',monospace;\">[Service]<\/span><\/div>\n<div><span style=\"--en-fontfamily: monospace; font-family: 'Source Code Pro',monospace;\">ExecStartPre=\/bin\/sh -c &#8220;\/usr\/sbin\/iptables -D FORWARD -p all -i br0 -j ACCEPT || true&#8221;<\/span><\/div>\n<div><span style=\"--en-fontfamily: monospace; font-family: 'Source Code Pro',monospace;\">ExecStartPre=\/usr\/bin\/iptables -A FORWARD -p all -i br0 -j ACCEPT<\/span><\/div>\n<div>\u00a0<\/div>\n<div><span style=\"--en-fontfamily: monospace; font-family: 'Source Code Pro',monospace;\">$ sudo reboot<\/span><\/div>\n<div>\u00a0<\/div>\n<div>This creates an overlay file to systemd&#8217;s docker settings, that will tweak the iptables firewall rules so that they work better with KVM. Change &#8220;br0&#8221; to your bridge device interface.<\/div>\n<div>\u00a0<\/div>\n<div>References: https:\/\/bbs.archlinux.org\/viewtopic.php?id=233727<\/div>\n<p>\u00a0<\/p>\n<p><i>Originally created with EverNote at 20201230T021302Z<\/i><\/p>\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"168\" src=\"https:\/\/blog.shahada.abubakar.net\/wp-content\/uploads\/2021\/12\/docker.png\" alt=\"\" class=\"wp-image-8802\"\/><\/figure><\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0 I recently enabled docker on my desktop PC running Ubuntu 20.04LTS &#8230; and it ended up breaking Bridged Networking on my VirtManager\/KVM Virtual Machines (NAT still works). It turns out that (1) docker&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":8802,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[213,116],"tags":[],"class_list":["post-8278","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-docker","category-linux"],"_links":{"self":[{"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=\/wp\/v2\/posts\/8278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8278"}],"version-history":[{"count":4,"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=\/wp\/v2\/posts\/8278\/revisions"}],"predecessor-version":[{"id":8982,"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=\/wp\/v2\/posts\/8278\/revisions\/8982"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=\/wp\/v2\/media\/8802"}],"wp:attachment":[{"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8278"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.shahada.abubakar.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}