# K8S outtrafic pod

**URL:** <https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658>\
**Category:** General Discussions\
**Created:** [November 13, 2019, 1:41pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658 "2019-11-13T13:41:29Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gidi_kalef/32/2884_2.png) [@Gidi\_Kalef](https://discuss.kubernetes.io/u/Gidi_Kalef)\
**Post date:** [November 13, 2019, 1:41pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/1 "2019-11-13T13:41:29Z")

</div>

Hi Guys,

i have a pod that need access to another service which managed under firewall .

currently we don’t have access to the another service because it blocked(by firewall), im trying to figure out which ip the pod use to identity against the another service to open the firewall rule needed.

any idea?

Thanks,  
Gidi

---

<div class="post-metadata">

**Author:** ![thockin](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/thockin/32/2457_2.png) [@thockin](https://discuss.kubernetes.io/u/thockin)\
**Post date:** [November 13, 2019, 4:23pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/2 "2019-11-13T16:23:21Z")

</div>

You’ll need some sort of explicit egress Gateway. This is not something Kubernetes has by default right now.

---

<div class="post-metadata">

**Author:** ![acim](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/acim/32/1955_2.png) [@acim](https://discuss.kubernetes.io/u/acim)\
**Post date:** [November 14, 2019, 1:53am UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/3 "2019-11-14T01:53:29Z")

</div>

If this is completely different machine, your pod will probably come from the external IP of the node it is running in. If you can’t find out, you can run some image with curl and find out your external ip from some whatismyip site.

---

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gidi_kalef/32/2884_2.png) [@Gidi\_Kalef](https://discuss.kubernetes.io/u/Gidi_Kalef)\
**Post date:** [November 14, 2019, 5:17am UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/4 "2019-11-14T05:17:31Z")

</div>

Hi @acim ,  
Thanks for your response, we have tried to open any any in firewall with source of our worker machines, with out successes.  
Can you please give me more information about the curl what should I do?  
Thanks

---

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gidi_kalef/32/2884_2.png) [@Gidi\_Kalef](https://discuss.kubernetes.io/u/Gidi_Kalef)\
**Post date:** [November 14, 2019, 5:18am UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/5 "2019-11-14T05:18:44Z")

</div>

@thockin Hi thockin ,  
thanks for you response, isnt the pod should use the external IP of the host it is running on?

---

<div class="post-metadata">

**Author:** ![acim](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/acim/32/1955_2.png) [@acim](https://discuss.kubernetes.io/u/acim)\
**Post date:** [November 14, 2019, 11:46am UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/6 "2019-11-14T11:46:07Z")

</div>

Is there some firewall protecting your Kubernetes cluster? Is it in some cloud or?  
Do you have network policies?

---

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gidi_kalef/32/2884_2.png) [@Gidi\_Kalef](https://discuss.kubernetes.io/u/Gidi_Kalef)\
**Post date:** [November 14, 2019, 12:37pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/7 "2019-11-14T12:37:26Z")

</div>

Actually my K8S is not protected under fire wall

 ![Capture](https://us1.discourse-cdn.com/flex016/uploads/kubernetes/original/2X/7/736b21d45b5fe5ac01a036e370d1a32df329dee5.png)

---

<div class="post-metadata">

**Author:** ![acim](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/acim/32/1955_2.png) [@acim](https://discuss.kubernetes.io/u/acim)\
**Post date:** [November 14, 2019, 1:00pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/8 "2019-11-14T13:00:11Z")

</div>

What errors do you see from your pod? What is the output of “kubectl logs” and “kubectl describe pod”?

Run this to find out your public IP:

kubectl run -ti --rm --restart Never --image curlimages/curl – curl [http://whatismyip.akamai.com](http://whatismyip.akamai.com)

---

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gidi_kalef/32/2884_2.png) [@Gidi\_Kalef](https://discuss.kubernetes.io/u/Gidi_Kalef)\
**Post date:** [November 14, 2019, 2:16pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/9 "2019-11-14T14:16:23Z")

</div>

i run:  
kubectl exec -ti bash  
then in the terminal i ran  
curl [http://whatismyip.akamai.com/](http://whatismyip.akamai.com/)

this is the respond: 194.31.58.5

is that the ip i have too look for?

---

<div class="post-metadata">

**Author:** ![acim](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/acim/32/1955_2.png) [@acim](https://discuss.kubernetes.io/u/acim)\
**Post date:** [November 14, 2019, 9:27pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/10 "2019-11-14T21:27:08Z")

</div>

Of course, allow this IP to access your external service and check your logs on both sides.

---

<div class="post-metadata">

**Author:** ![acim](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/acim/32/1955_2.png) [@acim](https://discuss.kubernetes.io/u/acim)\
**Post date:** [November 15, 2019, 12:03pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/11 "2019-11-15T12:03:02Z")

</div>

Take care that each node probably has it’s own external IP. You can maybe get all of them using this command:

`kubectl get nodes -o jsonpath='{.items[*].status.addresses[?(@.type=="ExternalIP")].address}'`

If this is not set, you have to find out all IP’s by running some curl pod on each node. You may need to use node selector.

---

<div class="post-metadata">

**Author:** ![Gidi\_Kalef](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gidi_kalef/32/2884_2.png) [@Gidi\_Kalef](https://discuss.kubernetes.io/u/Gidi_Kalef)\
**Post date:** [November 17, 2019, 12:46pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/12 "2019-11-17T12:46:02Z")

</div>

> [@acim](#):
>
> ExternalIP

@acim  
i havent found any external ip ☹  
should i run the curl from the pod in each node, or on the node?

Thanks

---

<div class="post-metadata">

**Author:** ![acim](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/acim/32/1955_2.png) [@acim](https://discuss.kubernetes.io/u/acim)\
**Post date:** [November 17, 2019, 10:15pm UTC](https://discuss.kubernetes.io/t/k8s-outtrafic-pod/8658/13 "2019-11-17T22:15:05Z")

</div>

Well, if this pod is runing as part of a deployment, than you should get external IP’s of all worker nodes and whitelist them on the external firewall. If you run a single pod always on the same node, then this one IP should be enough.
