# Firewall woes in Centos 7

**URL:** <https://forums.suse.com/t/firewall-woes-in-centos-7/382>\
**Category:** Rancher 1.x\
**Created:** [September 2, 2015, 2:29pm UTC](https://forums.suse.com/t/firewall-woes-in-centos-7/382 "2015-09-02T14:29:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kiboro](https://avatars.discourse-cdn.com/v4/letter/k/7993a0/32.png) [@kiboro](https://forums.suse.com/u/kiboro)\
**Post date:** [September 2, 2015, 2:29pm UTC](https://forums.suse.com/t/firewall-woes-in-centos-7/382/1 "2015-09-02T14:29:32Z")

</div>

I’m using Centos 7 as a host for rancher hosts and having serious firewall problems.

In short I have to set both the INPUT and the FORWARD chains to ACCEPT to make Rancher work. That cannot stay like that in production. What do I need to add as more restrictive rules to allow external access to containers and also access between containers? I’ve tried a lot of options but failed.

---

<div class="post-metadata">

**Author:** ![ibuildthecloud](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/ibuildthecloud/32/8_2.png) [@ibuildthecloud](https://forums.suse.com/u/ibuildthecloud)\
**Post date:** [September 3, 2015, 8:35pm UTC](https://forums.suse.com/t/firewall-woes-in-centos-7/382/2 "2015-09-03T20:35:26Z")

</div>

INPUT could be set to DENY. I don’t see an issue with that, but haven’t tried it out. To make forwarding easier we can change our iptables in the CATTLE\_PREROUTING to set a mark. You would then need to accept forward traffic that matches our mark.

---

<div class="post-metadata">

**Author:** ![kiboro](https://avatars.discourse-cdn.com/v4/letter/k/7993a0/32.png) [@kiboro](https://forums.suse.com/u/kiboro)\
**Post date:** [September 4, 2015, 9:54am UTC](https://forums.suse.com/t/firewall-woes-in-centos-7/382/3 "2015-09-04T09:54:27Z")

</div>

Thanks for the reply. I’m nowhere near a wizard on iptables and your natting is beyond me so I was struggling a bit. When I tested I thought that FORWARD DENY was stopping communications between containers and INPUT DENY was stopping me accessing containers externally.

Thinking about it further I guess the latter part is just that I need the usual external firewall rules as if the services were running on the host.

If you could work out a better way of handling the FORWARD part then I would be grateful.

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [September 25, 2015, 5:10pm UTC](https://forums.suse.com/t/firewall-woes-in-centos-7/382/4 "2015-09-25T17:10:51Z")

</div>

@kiboro I’ve created a GitHub issue for us to track for when we can look into firewall rules.

> <https://github.com/rancher/rancher/issues/2145>
>
> Per: http://forums.suse.com/t/firewall-woes-in-centos-7/382/3
> Possibly set a "mark" on our forwarding rules that others could then use in making firewall decisions.
