# Restricting access to exposed services

**URL:** <https://forums.suse.com/t/restricting-access-to-exposed-services/10047>\
**Category:** Rancher 1.x\
**Created:** [April 11, 2018, 2:49pm UTC](https://forums.suse.com/t/restricting-access-to-exposed-services/10047 "2018-04-11T14:49:28Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![elisiariocouto](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/elisiariocouto/32/3899_2.png) [@elisiariocouto](https://forums.suse.com/u/elisiariocouto)\
**Post date:** [April 11, 2018, 2:49pm UTC](https://forums.suse.com/t/restricting-access-to-exposed-services/10047/1 "2018-04-11T14:49:29Z")

</div>

Hello.

I have several bare metal servers running a bunch of different environments (all Cattle). I have a staging environment with some services exposed that I want to only be accessible through a set of IPs. I searched about this and the only thing I’ve encountered was this issue: [How to restrict access to service via iptables?](http://forums.suse.com/t/how-to-restrict-access-to-service-via-iptables/249). My goal is to invert the “docker behaviour”, I want to drop every connection to every port unless it comes from a trusted IP. I also saw an open issue for a CATTLE\_USER chain, similar to DOCKER\_USER that I think that would solve the problem, but it is not scheduled to any milestone.

Is the mangle table the way to go for these cases?
