5.13 Bind incoming container traffic to a specific host interface

Information

https://docs.docker.com/articles/networking/#binding-container-ports-to-the-host

Solution

Bind the container port to a specific host interface on the desired host port.For example,docker run --detach --publish 10.2.3.4-49153-80 nginxIn the example above, the container port 80 is bound to the host port on 49153 and would
accept incoming connection only from 10.2.3.4 external interface.Impact-None.Default Value-By default, Docker exposes the container ports on 0.0.0.0, the wildcard IP address that
will match any possible incoming network interface on the host machine.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 9749cf8d805868d7a9ad511bd269775f3c2bf5b1a115be68d0a3a06c6f18d6a4