2 ms·
It has to do with the implementation of the networking. The DOCKER chain in the nat table gets hit by inbound traffic on the PREROUTING chain before UFW's chain
by hxtk 6y ago
It has to do with the implementation of the networking. The DOCKER chain in the nat table gets hit by inbound traffic on the PREROUTING chain before UFW's chains on the filter table. IIRC, can get around this by directing UFW to write its rules to the DOCKER-USER chain.
Firewalld is implemented differently and will exhibit the expected blocking behavior: traffic targeting docker ports will encounter firewalld before it encounters docker.