Docker containers and KVM VMs on host bridge in a single system causes firewall REJECT

Solution Verified - Updated -


  • When docker is started, KVM VM can not route outside of hypervisor's bridge.
  • ssh from outside the host returns No route to host
$ ssh root@
ssh: connect to host port 22: No route to host
  • ping from outside the host is successful
$ ping
PING ( 56(84) bytes of data.
64 bytes from icmp_seq=1 ttl=64 time=0.761 ms
64 bytes from icmp_seq=2 ttl=64 time=0.661 ms
--- ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1000ms
rtt min/avg/max/mdev = 0.661/0.711/0.761/0.050 ms


  • Red Hat Enterprise Linux 7
  • KVM VM on host provided bridge (not on bridge managed by libvirtd.)
  • systemd docker.service started.

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In