Kali部署CTF容器遇Docker路由冲突错误求助
Kali Linux下CTF容器部署Docker路由冲突问题
问题描述
在Kali机器上部署CTF相关容器时,执行make up命令触发Docker路由冲突错误,提示信息为cannot program address 172.19.0.3/16 in sandbox interface because it conflicts with existing route。已尝试重装Docker、调整子网、通过ChatGPT排查,均未解决问题。确认docker-compose.yaml文件可在其他环境正常运行,容器需按指定网络拓扑创建3个互联节点。
命令执行错误输出
$ make up docker info >/dev/null 2>/dev/null Environment created. docker network prune -f docker-compose up -d Creating network "challenge_files_a00_ext" with driver "bridge" Creating network "challenge_files_a10_net1" with driver "macvlan" Creating network "challenge_files_a20_net2" with driver "macvlan" Creating challenge_files_node1_1 ... Creating challenge_files_node3_1 ... done Creating challenge_files_node2_1 ... error ERROR: for challenge_files_node2_1 Cannot start service node2: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth5913ce4 to sandbox: error setting interface "veth5913ce4Creating challenge_files_node1_1 ... error because it conflicts with existing route {Ifindex: 12 Dst: 0.0.0.0/0 Src: <nil> Gw: 172.18.0.1 Flags: [] Table: 254 Realm: 0}: unknown ERROR: for challenge_files_node1_1 Cannot start service node1: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth0e8efb6 to sandbox: error setting interface "veth0e8efb6" IP to 172.18.0.3/16: cannot program address 172.18.0.3/16 in sandbox interface because it conflicts with existing route {Ifindex: 10 Dst: 0.0.0.0/0 Src: <nil> Gw: 192.168.123.1 Flags: [] Table: 254 Realm: 0}: unknown ERROR: for node2 Cannot start service node2: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth5913ce4 to sandbox: error setting interface "veth5913ce4" IP to 172.19.0.3/16: cannot program address 172.19.0.3/16 in sandbox interface because it conflicts with existing route {Ifindex: 12 Dst: 0.0.0.0/0 Src: <nil> Gw: 172.18.0.1 Flags: [] Table: 254 Realm: 0}: unknown ERROR: for node1 Cannot start service node1: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth0e8efb6 to sandbox: error setting interface "veth0e8efb6" IP to 172.18.0.3/16: cannot program address 172.18.0.3/16 in sandbox interface because it conflicts with existing route {Ifindex: 10 Dst: 0.0.0.0/0 Src: <nil> Gw: 192.168.123.1 Flags: [] Table: 254 Realm: 0}: unknown ERROR: Encountered errors while bringing up the project. make: *** [Makefile:14: up] Error 1
本地路由表信息(route -n输出)
Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 0.0.0.0 192.168.0.1 0.0.0.0 UG 600 0 0 wlan0 172.17.0.0 0.0.0.0 255.255.0.0 U 0 0 0 docker0 192.168.0.0 0.0.0.0 255.255.255.0 U 600 0 0 wlan0
docker-compose.yaml配置内容
version: "3" services: node1: build: context: ./ubuntu-ccit dockerfile: Dockerfile image: ubuntu-ccit hostname: node1 volumes: - ./src:/src privileged: true environment: - ROOTPW=ccit networks: a00_ext: ipv4_address: 192.168.123.123 a10_net1: node2: build: context: ./ubuntu-ccit dockerfile: Dockerfile image: ubuntu-ccit hostname: node2 privileged: true volumes: - ./src:/src environment: - ROOTPW=ccit - REMIP=1 networks: a10_net1: a20_net2: node3: build: context: ./ubuntu-ccit dockerfile: Dockerfile image: ubuntu-ccit hostname: node3 volumes: - ./src:/src privileged: true environment: - ROOTPW=ccit - REMIP=1 networks: a20_net2: networks: a00_ext: driver: bridge ipam: driver: default config: - subnet: 192.168.123.0/24 a10_net1: driver: macvlan driver_opts: parent: ccit-net.10 a20_net2: driver: macvlan driver_opts: parent: ccit-net.20
排查与解决建议
- 检查macvlan父接口:确认
ccit-net.10和ccit-net.20这两个VLAN子接口是否存在且正常启用。执行ip link show查看接口列表,若不存在则手动创建:ip link add link wlan0 name ccit-net.10 type vlan id 10 ip link add link wlan0 name ccit-net.20 type vlan id 20 ip link set ccit-net.10 up ip link set ccit-net.20 up - 修正a00_ext子网冲突:宿主机所在子网为
192.168.0.0/24,但a00_ext配置为192.168.123.0/24,错误提示中出现192.168.123.1网关冲突。建议调整a00_ext子网为不重叠段,比如192.168.124.0/24,同时更新node1的ipv4_address为192.168.124.123。 - 指定macvlan子网段:当前
a10_net1和a20_net2未配置IPAM,Docker自动分配的172.18.0.0/16、172.19.0.0/16与现有路由冲突。手动指定专属子网:a10_net1: driver: macvlan driver_opts: parent: ccit-net.10 ipam: driver: default config: - subnet: 192.168.10.0/24 a20_net2: driver: macvlan driver_opts: parent: ccit-net.20 ipam: driver: default config: - subnet: 192.168.20.0/24 - 清理残留配置并重启Docker:执行
docker network prune -f清理无用网络,再重启Docker服务:
之后重新执行systemctl restart dockermake up。
内容的提问来源于stack exchange,提问作者Lemon51
相关产品推荐
相关产品推荐

