# Restrict access to a docker machine

**URL:** <https://forums.suse.com/t/restrict-access-to-a-docker-machine/1922>\
**Category:** Rancher 1.x\
**Created:** [March 2, 2016, 3:44pm UTC](https://forums.suse.com/t/restrict-access-to-a-docker-machine/1922 "2016-03-02T15:44:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shakisha](https://avatars.discourse-cdn.com/v4/letter/s/b9e5f3/32.png) [@shakisha](https://forums.suse.com/u/shakisha)\
**Post date:** [March 2, 2016, 3:44pm UTC](https://forums.suse.com/t/restrict-access-to-a-docker-machine/1922/1 "2016-03-02T15:44:06Z")

</div>

I have got an nginx docker container an I want only some IP addresses be able to access to that.  
How I can make it possible from rancher?

What is the best practice to make a rancher machine sure ? (about networking)

---

<div class="post-metadata">

**Author:** ![clescot](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/clescot/32/317_2.png) [@clescot](https://forums.suse.com/u/clescot)\
**Post date:** [March 3, 2016, 3:08pm UTC](https://forums.suse.com/t/restrict-access-to-a-docker-machine/1922/2 "2016-03-03T15:08:18Z")

</div>

Hi,  
for your information, it is not yet possible to communicate only via some private network interfaces ([Is it possible to select on which network interface open ports?](http://forums.suse.com/t/is-it-possible-to-select-on-which-network-interface-open-ports/1831)).  
One option is to restrict access via some configuration external to docker (ufw ou iptable directly), and you must set the `--iptables=false` option in your `/etc/default/docker` config file (but you will have to manage every docker communication ).  
Hope it helps,

Charles.

---

<div class="post-metadata">

**Author:** ![shakisha](https://avatars.discourse-cdn.com/v4/letter/s/b9e5f3/32.png) [@shakisha](https://forums.suse.com/u/shakisha)\
**Post date:** [March 3, 2016, 3:19pm UTC](https://forums.suse.com/t/restrict-access-to-a-docker-machine/1922/3 "2016-03-03T15:19:45Z")

</div>

no other way?

Manually doing in iptables it’s hard, especially in case of many containers running

---

<div class="post-metadata">

**Author:** ![shakisha](https://avatars.discourse-cdn.com/v4/letter/s/b9e5f3/32.png) [@shakisha](https://forums.suse.com/u/shakisha)\
**Post date:** [March 4, 2016, 1:45am UTC](https://forums.suse.com/t/restrict-access-to-a-docker-machine/1922/4 "2016-03-04T01:45:34Z")

</div>

i’ve found this 🙂

- 

Starting with Docker 1.2 you can now run your image with parameters --cap-add=NET\_ADMIN --cap-add=NET\_RAW which will allow internal iptables.

So, will it work ok my scenario?
