You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker配置:限制8080端口仅允许指定内网访问,禁止外部访问

Got it, let's break down your problem and fix this. The core issue here is that your ovpn_admin container uses the container:openvpn network mode, meaning it shares the exact same network stack as the openvpn container. Binding the port to 127.0.0.1 makes it only accessible from the host itself—not your local LAN, which isn't what you want. Here are two solid, actionable solutions to restrict port 8080 exclusively to the 192.168.250.0/24 network:

Solution 1: Use iptables Firewall Rules (No Container Restarts Needed)

This is the quickest fix since you don't have to disrupt running services. We'll explicitly allow your local LAN to access port 8080, then block all other incoming traffic to that port.

  1. First, allow traffic from your LAN subnet to port 8080:
sudo iptables -A INPUT -p tcp --dport 8080 -s 192.168.250.0/24 -j ACCEPT
  1. Next, drop all other incoming requests to port 8080:
sudo iptables -A INPUT -p tcp --dport 8080 -j DROP
  1. Save the rules to ensure they persist after a host reboot:
    • For Debian/Ubuntu systems:
      sudo netfilter-persistent save
      
    • For RHEL/CentOS systems:
      sudo iptables-save > /etc/sysconfig/iptables
      

Solution 2: Bind Port 8080 to Your Host's LAN IP (Requires Container Restart)

Since your host's eth0 interface has a LAN IP of 192.168.250.5, we can modify the openvpn container's port mapping to bind 8080 only to this IP. This ensures the port is never exposed to external networks at all.

  1. Stop and remove your existing containers (your data is safe thanks to the mounted volumes):
docker stop ovpn_admin openvpn
docker rm ovpn_admin openvpn
  1. Recreate the openvpn container with the updated port mapping:
docker run --name openvpn \
 -v /root/easyrsa_master:/etc/openvpn/easyrsa \
 -v /root/ccd_master:/etc/openvpn/ccd \
 -e OVPN_SERVER_NET='192.168.100.0' \
 -e OVPN_SERVER_MASK='255.255.255.0' \
 -p 7777:1194 \
 -p 192.168.250.5:8080:8080 \
 --net test \
 --cap-add=NET_ADMIN \
 openvpn:local
  1. Recreate the ovpn_admin container (its network mode remains unchanged since it shares the openvpn stack):
docker run --name ovpn_admin \
 -v /root/easyrsa_master:/mnt/easyrsa \
 -v /root/ccd_master:/mnt/ccd \
 -e OVPN_CCD="True" \
 -e OVPN_CCD_PATH="/mnt/ccd" \
 -e EASYRSA_PATH="/mnt/easyrsa" \
 -e OVPN_DEBUG="True" \
 -e OVPN_VERBOSE="True" \
 -e OVPN_NETWORK="192.168.100.0/24" \
 -e OVPN_SERVER="<external_address>:7777:tcp" \
 -e OVPN_INDEX_PATH="/mnt/easyrsa/pki/index.txt" \
 --network="container:openvpn" \
 ovpn-admin:local

Quick Note on Why 127.0.0.1:8080:8080 Didn't Work

When you bind a port to 127.0.0.1, it's only accessible via the host's loopback interface. That means even devices on your local 192.168.250.0/24 network can't reach it—only processes running directly on the host itself. Neither of the solutions above have this limitation.

内容的提问来源于stack exchange,提问作者ISH91

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 17:02:42