You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kali部署CTF容器遇Docker路由冲突错误求助

Kali Linux下CTF容器部署Docker路由冲突问题

问题描述

在Kali机器上部署CTF相关容器时,执行make up命令触发Docker路由冲突错误,提示信息为cannot program address 172.19.0.3/16 in sandbox interface because it conflicts with existing route。已尝试重装Docker、调整子网、通过ChatGPT排查,均未解决问题。确认docker-compose.yaml文件可在其他环境正常运行,容器需按指定网络拓扑创建3个互联节点。

命令执行错误输出

$ make up                
docker info >/dev/null 2>/dev/null
Environment created.
docker network prune -f
docker-compose up -d
Creating network "challenge_files_a00_ext" with driver "bridge"
Creating network "challenge_files_a10_net1" with driver "macvlan"
Creating network "challenge_files_a20_net2" with driver "macvlan"
Creating challenge_files_node1_1 ... 
Creating challenge_files_node3_1 ... done
Creating challenge_files_node2_1 ... error

ERROR: for challenge_files_node2_1  Cannot start service node2: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth5913ce4 to sandbox: error setting interface "veth5913ce4Creating challenge_files_node1_1 ... error
 because it conflicts with existing route {Ifindex: 12 Dst: 0.0.0.0/0 Src: <nil> Gw: 172.18.0.1 Flags: [] Table: 254 Realm: 0}: unknown

ERROR: for challenge_files_node1_1  Cannot start service node1: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth0e8efb6 to sandbox: error setting interface "veth0e8efb6" IP to 172.18.0.3/16: cannot program address 172.18.0.3/16 in sandbox interface because it conflicts with existing route {Ifindex: 10 Dst: 0.0.0.0/0 Src: <nil> Gw: 192.168.123.1 Flags: [] Table: 254 Realm: 0}: unknown

ERROR: for node2  Cannot start service node2: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth5913ce4 to sandbox: error setting interface "veth5913ce4" IP to 172.19.0.3/16: cannot program address 172.19.0.3/16 in sandbox interface because it conflicts with existing route {Ifindex: 12 Dst: 0.0.0.0/0 Src: <nil> Gw: 172.18.0.1 Flags: [] Table: 254 Realm: 0}: unknown

ERROR: for node1  Cannot start service node1: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error running hook #0: error running hook: exit status 1, stdout: , stderr: failed to add interface veth0e8efb6 to sandbox: error setting interface "veth0e8efb6" IP to 172.18.0.3/16: cannot program address 172.18.0.3/16 in sandbox interface because it conflicts with existing route {Ifindex: 10 Dst: 0.0.0.0/0 Src: <nil> Gw: 192.168.123.1 Flags: [] Table: 254 Realm: 0}: unknown
ERROR: Encountered errors while bringing up the project.
make: *** [Makefile:14: up] Error 1

本地路由表信息(route -n输出)

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         192.168.0.1     0.0.0.0         UG    600    0        0 wlan0
172.17.0.0      0.0.0.0         255.255.0.0     U     0      0        0 docker0
192.168.0.0     0.0.0.0         255.255.255.0   U     600    0        0 wlan0

docker-compose.yaml配置内容

version: "3"

services:
  node1:
    build: 
      context: ./ubuntu-ccit
      dockerfile: Dockerfile
    image: ubuntu-ccit
    hostname: node1
    volumes:
      - ./src:/src
    privileged: true
    environment:
     - ROOTPW=ccit
    networks:
     a00_ext:
      ipv4_address: 192.168.123.123
     a10_net1:

  node2:
    build: 
      context: ./ubuntu-ccit
      dockerfile: Dockerfile
    image: ubuntu-ccit
    hostname: node2
    privileged: true
    volumes:
      - ./src:/src
    environment:
     - ROOTPW=ccit
     - REMIP=1
    networks:
     a10_net1:
     a20_net2:

  node3:
    build: 
      context: ./ubuntu-ccit
      dockerfile: Dockerfile
    image: ubuntu-ccit
    hostname: node3
    volumes:
      - ./src:/src
    privileged: true
    environment:
     - ROOTPW=ccit
     - REMIP=1
    networks:
     a20_net2:

networks:
  a00_ext:
   driver: bridge
   ipam:
    driver: default
    config:
     - subnet: 192.168.123.0/24

  a10_net1:
   driver: macvlan
   driver_opts:
     parent: ccit-net.10

  a20_net2:
   driver: macvlan
   driver_opts:
     parent: ccit-net.20

排查与解决建议

  • 检查macvlan父接口:确认ccit-net.10和ccit-net.20这两个VLAN子接口是否存在且正常启用。执行ip link show查看接口列表,若不存在则手动创建:
    ip link add link wlan0 name ccit-net.10 type vlan id 10
    ip link add link wlan0 name ccit-net.20 type vlan id 20
    ip link set ccit-net.10 up
    ip link set ccit-net.20 up
    
  • 修正a00_ext子网冲突:宿主机所在子网为192.168.0.0/24,但a00_ext配置为192.168.123.0/24,错误提示中出现192.168.123.1网关冲突。建议调整a00_ext子网为不重叠段,比如192.168.124.0/24,同时更新node1的ipv4_address为192.168.124.123。
  • 指定macvlan子网段:当前a10_net1和a20_net2未配置IPAM,Docker自动分配的172.18.0.0/16、172.19.0.0/16与现有路由冲突。手动指定专属子网:
    a10_net1:
      driver: macvlan
      driver_opts:
        parent: ccit-net.10
      ipam:
        driver: default
        config:
          - subnet: 192.168.10.0/24
    a20_net2:
      driver: macvlan
      driver_opts:
        parent: ccit-net.20
      ipam:
        driver: default
        config:
          - subnet: 192.168.20.0/24
    
  • 清理残留配置并重启Docker:执行docker network prune -f清理无用网络,再重启Docker服务:
    systemctl restart docker
    
    之后重新执行make up。

内容的提问来源于stack exchange,提问作者Lemon51

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 02:53:12