Traefik with Portainer container doable on FWG?

Comments

38 comments

  • Avatar
    Kay

    Thank you. I figured it out too.  On the server I used cloudflare's dns on the network settings.  When I changed it to FWG it worked.  You made a good choice going with Traefik rather than NPM in my view.

    0
    Comment actions Permalink
  • Avatar
    DeltaV

    Kay, can you go into some details about how you got it working? I'm currently running into the exact same issue.

    0
    Comment actions Permalink
  • Avatar
    Kay

    I am not running Traefik on the FWG as I do not think its a good idea.  Generally I feel running things on the FWG and if not configured properly or there is a bug in the software, you can compromise your security.

    The problem is that I am running Traefik on an internal host on my home network and that host was set to use cloudflare's dns rather than the FWG.  I changed the server running Traefik to query the FWG dns and it worked. I just made sure that all my internal clients use the FWG for DNS queries.

    Getting up to speed with Traefik can be a pain in the proverbial rear end but its totally supreme compared to NPM or any other solution so just persevere. 

    0
    Comment actions Permalink
  • Avatar
    DeltaV

    Hi Kay,

    That makes sense. I'm actually doing the same thing - running it on a small home server rather than the FWG - was mostly asking because I was getting the same error with getting certificates on that machine. I'll need to look into setting the DNS on it to FWG. I was finally able to let it get a certificate by turning off Monitoring on the device in FW app, but that's obviously not a long-term solution.

    Edit: Just checked on my server with 

    cat /run/systemd/resolve/resolv.conf

    and it's pointing at the FWG IP address. 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Are you running the FWG in router mode? what DNS are you using?

    0
    Comment actions Permalink
  • Avatar
    DeltaV

    Yes, it's in Router Mode. Under DNS Service I have "DNS over HTTPS" set to On with Cloudflare, Google, and Quad9 enabled, but not applying to that machine. For the network itself, I have DHCP Server set to "On" and the Primary DNS Server set to the IP of the FWG+. I do not have a Secondary DNS Server set - could that be causing the issue?

    Edit: On WAN I have both Primary and Secondary DNS set, but I'm guessing those were set automatically by my ISP. I don't recognize the IP addresses listed there.

    0
    Comment actions Permalink
  • Avatar
    Kay

    I dont think you need to turn of Monitoring for the device.  Just make sure that the DNS resolver on it is pointed to 192.168.X.X or whatever the internal address of the FWG is and it should be ok.

    Let me know how you get on.

    0
    Comment actions Permalink
  • Avatar
    Kay

    DOH or Unbound does not affect it at my end here.  It has been stable and works really well for me since I made those changes.

    0
    Comment actions Permalink

Please sign in to leave a comment.