5.9 Do not share the host's network namespace

Information

http://docs.docker.com/articles/networking/#how-docker-networks-a-container
2.https://github.com/docker/docker/issues/6401

Solution

Do not pass '--net=host' option when starting the container.Impact-None.Default Value-By default, container connects to Docker bridge.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-39

Plugin: Unix

Control ID: e965bd485c666148b516a1bfc0c2158f9751fbe0c48edacb825f861212d1918e