Table of Contents
Problem description:
问题解决
问题补充:
Home Operation and Maintenance Docker What should I do if docker cannot ping the host?

What should I do if docker cannot ping the host?

Jan 04, 2022 pm 04:58 PM
docker ping

Solutions to the problem that docker cannot ping the host: 1. Modify daemon.json; 2. Turn off the firewall; 3. Modify sysctl.conf; 4. Reset the network bridge.

What should I do if docker cannot ping the host?

The operating environment of this article: ubuntu16.04 system, Docker 20.10.11, Dell G3 computer.

What should I do if docker cannot ping the host?

Docker bridge mode cannot ping the host

Problem description:

 DockerThe network mode is divided into four types. Generally, when we do not set it, the default is bridgesingle bridge mode, the container uses an independent network Namespace and is connected to the docker0 virtual network card. Communicate with the host through the docker0 bridge and Iptables nat table configuration.
  At this time, test on the bastion machine and use busybox to test:

# 拉取镜像
docker pull busybox
# 运行容器
docker run -itd --name busy_bridge busybox
Copy after login

  Instruction docker network inspect bridge Check the network:
What should I do if docker cannot ping the host?

## The network configuration is successful. Go inside the container and check

ip. You can see that ip has been allocated, but ping fails when pinging the external network and cannot Connect to the external network:
What should I do if docker cannot ping the host?

 But when you conduct the same test locally or on Alibaba Cloud, you find that you can connect to the network. What is the problem?

Problem Analysis:

After finding information on the Internet, many people restart

docker, and then they can connect. Usually it is because a certain configuration is modified and then Restarting works, it has no effect here. Generally, there are several types of modifications. Try them one by one below:

  1. Modifydaemon.json
The container cannot access the host because the network segment allocated by the bridge conflicts with the host. You need to modify

daemon.json to specify the allocation. Use the command vim /etc/docker/daemon.jsonAdd after entering:

{"bip":"172.16.10.1/24"}
Copy after login
 Although you can access it by restarting

docker and creating a container, there is no conflict at all between the ip assigned by the original bastion host and the container. The method doesn’t work.

  1. Turn off the firewall
The container cannot access the host through the bridge, and therefore cannot access the external network. The firewall may be blocking access, so you can turn it off Firewall or open a certain port. Tested on the server, turned on the firewall, and found that the container was indeed unable to access the Baidu homepage and the host. After closing the firewall and restarting

docker, the container could be accessed normally.  However, the firewall on the bastion machine is originally turned off, so this method is useless.

  1. Modifysysctl.conf
  2. ##  
docker

The internal network of the host is normal, and the network with other hosts is normal. The connection fails. Other hosts cannot connect to the port mapped on the docker host, and docker cannot connect to external hosts internally. Use the docker info command to check the information and find the following error: <div class="code" style="position:relative; padding:0px; margin:0px;"><pre class="brush:php;toolbar:false">WARNING: IPv4 forwarding is disabled WARNING: bridge-nf-call-iptables is disabled WARNING: bridge-nf-call-ip6tables is disabled</pre><div class="contentsignin">Copy after login</div></div>  Use the command

vim /etc/sysctl.conf

Edit the configuration file and add the following code to the file: <div class="code" style="position:relative; padding:0px; margin:0px;"><pre class="brush:php;toolbar:false">net.bridge.bridge-nf-call-ip6tables=1 net.bridge.bridge-nf-call-iptables=1 net.bridge.bridge-nf-call-arptables=1 net.ipv4.ip_forward=1</pre><div class="contentsignin">Copy after login</div></div>  Then use the command

systemctl restart network

Restart the network and check docker info again, the warning disappears. But it's still useless. The container on the bastion machine still cannot access the host machine through the bridge and cannot access the external network.

    Reset the bridge
  1. After using the command
yum install bridge-utils

to install the tool, use brctl show Check the network bridge and you can find:
Use the What should I do if docker cannot ping the host?docker network create [bridge name]
command to create a new network bridge and find the generated bridge id is still 8000.0000000000, create a container on the new bridge, and check again and there is no change, indicating that it is probably a problem with the bridge.  Test again. At this time, the bridge ip
is 172.17.0.1 and the container ip is 172.0.0.2. The host function is found. ping The network bridge is connected, but the container cannot be connected. The container cannot connect to the network bridge and cannot connect to the host, let alone the external network, so there must be a problem with the network bridge. <h3 id="问题解决">问题解决</h3> <p>  这里<code>docker network生成新的网桥不行,说明dockernetwork存在问题,我们利用刚才下载的bridge-utils来创建网桥。
  首先暂停docker服务,利用指令:

service docker stop
Copy after login

  添加网桥:

brctl addbr br0
Copy after login

  添加ip字段:

ip addr add 172.16.0.1/24 dev br0
Copy after login

  启用网桥br0

ip link set dev br0 up
Copy after login

  查看网络br0
What should I do if docker cannot ping the host?

  修改docker默认网桥:

vim /etc/docker/daemon.json
Copy after login

  添加字段:

"bridge":"br0"
Copy after login

  重启docker

service docker start
Copy after login

  此时查看网桥:
What should I do if docker cannot ping the host?

  在没有挂载容器前,依旧是8000.000000000000。运行测试容器:

docker run -itd --name busy_test busybox
Copy after login

  查看What should I do if docker cannot ping the host?:
What should I do if docker cannot ping the host?

  此时容器挂载在网桥上了,再次查看网桥id
What should I do if docker cannot ping the host?

  说明已经其作用,进入测试容器内部,What should I do if docker cannot ping the host?:
What should I do if docker cannot ping the host?

  成功!
  补充:这里使用docker network新建网桥,没有用,发现新建网桥挂载容器后,其bridge id依旧不变,没有起作用,说明堡垒机上的docker network可能存在问题。

问题补充:

  上面的问题是创建自定义网桥,然后在自定义网桥上连接容器ab,结果宿主机无法pingab,且进入容器内部后,两个容器无法ping通自定义网络,但能彼此相通。
  查了很多资料,发现了这篇文章。博主说问题原因是系统内核的网桥模块bridge.ko加载失败导致,解决问题的方案是升级内核或升级系统。
  升级centos内核参考这篇。
  升级完成后,重装Docker,自定义网桥和容器,成功!不再有网络问题。

推荐学习:《docker视频教程

The above is the detailed content of What should I do if docker cannot ping the host?. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
1 months ago By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. Best Graphic Settings
1 months ago By 尊渡假赌尊渡假赌尊渡假赌
Will R.E.P.O. Have Crossplay?
1 months ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

How to read the docker version How to read the docker version Apr 15, 2025 am 11:51 AM

To get the Docker version, you can perform the following steps: Run the Docker command "docker --version" to view the client and server versions. For Mac or Windows, you can also view version information through the Version tab of the Docker Desktop GUI or the About Docker Desktop menu.

How to view logs from docker How to view logs from docker Apr 15, 2025 pm 12:24 PM

The methods to view Docker logs include: using the docker logs command, for example: docker logs CONTAINER_NAME Use the docker exec command to run /bin/sh and view the log file, for example: docker exec -it CONTAINER_NAME /bin/sh ; cat /var/log/CONTAINER_NAME.log Use the docker-compose logs command of Docker Compose, for example: docker-compose -f docker-com

How to create a mirror in docker How to create a mirror in docker Apr 15, 2025 am 11:27 AM

Steps to create a Docker image: Write a Dockerfile that contains the build instructions. Build the image in the terminal, using the docker build command. Tag the image and assign names and tags using the docker tag command.

How to use docker desktop How to use docker desktop Apr 15, 2025 am 11:45 AM

How to use Docker Desktop? Docker Desktop is a tool for running Docker containers on local machines. The steps to use include: 1. Install Docker Desktop; 2. Start Docker Desktop; 3. Create Docker image (using Dockerfile); 4. Build Docker image (using docker build); 5. Run Docker container (using docker run).

How to change the docker image source in China How to change the docker image source in China Apr 15, 2025 am 11:30 AM

You can switch to the domestic mirror source. The steps are as follows: 1. Edit the configuration file /etc/docker/daemon.json and add the mirror source address; 2. After saving and exiting, restart the Docker service sudo systemctl restart docker to improve the image download speed and stability.

How to check the name of the docker container How to check the name of the docker container Apr 15, 2025 pm 12:21 PM

You can query the Docker container name by following the steps: List all containers (docker ps). Filter the container list (using the grep command). Gets the container name (located in the "NAMES" column).

How to build a private repository by docker How to build a private repository by docker Apr 15, 2025 am 11:06 AM

You can build Docker private repositories to securely store and manage container images, providing strict control and security. The steps include: creating a repository, granting access, deploying a repository, pushing an image, and pulling an image. Advantages include security, version control, reduced network traffic and customization.

How to update the image of docker How to update the image of docker Apr 15, 2025 pm 12:03 PM

The steps to update a Docker image are as follows: Pull the latest image tag New image Delete the old image for a specific tag (optional) Restart the container (if needed)

See all articles