Question

Firewall on VPC internet gateway blocking backend droplets internet connection

Posted October 29, 2020 110 views
DigitalOcean VPC

I’ve set up a VPC with two droplets following the article at https://www.digitalocean.com/docs/networking/vpc/resources/droplet-as-gateway/. I have a problem where backend droplet cannot connect to the Internet through the gateway when firewall is enabled on the gateway droplet.

Firewall rules on the gateway allow access from anywhere on usual ssh, http and https ports. When I disable the firewall on the gateway, backend droplets can connect to the internet without a problem.

What should I change so that backend droplets can connect to the Internet through the gateway with its firewall enabled?

Thanks in advance!

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

×
1 answer

I found that ufw blocks routed traffic by default, so rules need to be added separately to allow such traffic to pass through.

https://askubuntu.com/questions/161346/how-to-configure-ufw-to-allow-ip-forwarding

Submit an Answer