Skip to content
Back to skills

Cis Docker 2.17

ASecurity

Ensure Userland Proxy is Disabled

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 3, 2026
securitygobashdockergitperformance

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-docker-2.17 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Docker 2.17?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Docker 2.17
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-docker-2-17/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-docker-2-17)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-docker-2.17
description: "Ensure Userland Proxy is Disabled"
category: cis-docker
version: "1.8.0"
author: cyberstrike-official
tags: [cis, docker, linux, containers, daemon-configuration, userland-proxy, networking]
cis_id: "2.17"
cis_benchmark: "CIS Docker Benchmark v1.8.0"
tech_stack: [linux, docker]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# Ensure Userland Proxy is Disabled (Manual)

## Profile Applicability

• Level 1 - Docker - Linux

## Description

The Docker daemon starts a userland proxy service for port forwarding whenever a port is exposed. Where hairpin NAT is available, this service is generally superfluous to requirements and can be disabled.

## Rationale

The Docker engine provides two mechanisms for forwarding ports from the host to containers, hairpin NAT, and the use of a userland proxy. In most circumstances, the hairpin NAT mode is preferred as it improves performance and makes use of native Linux iptables functionality instead of using an additional component.

Where hairpin NAT is available, the userland proxy should be disabled on startup to reduce the attack surface of the installation.

## Impact

Some systems with older Linux kernels may not be able to support hairpin NAT and therefore require the userland proxy service. Also, some networking setups can be impacted by the removal of the userland proxy.

## Audit Procedure

To confirm this setting, you should review the dockerd start-up options and any settings in `/etc/docker/daemon.json`.

To review the dockerd startup options, use:

```bash
ps -ef | grep dockerd
```

Ensure that the `--userland-proxy` parameter is set to `false`.

The contents of `/etc/docker/daemon.json` should also be reviewed for this setting.

## Remediation

You should run the Docker daemon as below:

```bash
dockerd --userland-proxy=false
```

## Default Value

By default, the userland proxy is enabled.

## References

1. http://windsock.io/the-docker-proxy/
2. https://github.com/docker/docker/issues/14856
3. https://github.com/docker/docker/issues/22741
4. https://docs.docker.com/config/containers/container-networking/

## CIS Controls

**Controls Version:** v8

**Control:** 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software

Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.

**IG 1:**
**IG 2:** ●
**IG 3:** ●

---

**Controls Version:** v7

**Control:** 9.2 Ensure Only Approved Ports, Protocols and Services Are Running

Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.

**IG 1:**
**IG 2:** ●
**IG 3:** ●

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…