Docker containers need networking to communicate with each other and the outside world. Understanding Docker's network model saves hours of debugging connectivity issues.
Network Drivers
# List networks
docker network ls
# Default networks
NETWORK ID NAME DRIVER
abc123 bridge bridge # Default for containers
def456 host host # Share host network
ghi789 none null # No networking| Driver | Use Case |
|---|---|
| bridge | Default. Containers on same host communicate |
| host | Container uses host's network stack directly |
| overlay | Multi-host networking (Swarm/K8s) |
| macvlan | Container gets its own MAC address on the LAN |
| none | No networking at all |
Bridge Networks
Default Bridge
# Containers on default bridge can reach each other by IP only
docker run -d --name web nginx
docker run -d --name api my-api
# Get container IP
docker inspect web -f '{{range.NetworkSettings.Networks}}{{.IPAddress}}{{end}}'
# 172.17.0.2
# api can reach web by IP (not name!)
docker exec api curl http://172.17.0.2User-Defined Bridge (Recommended)
# Create custom network
docker network create app-net
# Containers get DNS resolution by name
docker run -d --name web --network app-net nginx
docker run -d --name api --network app-net my-api
# api can reach web by name!
docker exec api curl http://webUser-defined bridges provide: - DNS resolution by container name - Better isolation from other containers - Network-level access control
Port Mapping
# Map host port 8080 to container port 80
docker run -d -p 8080:80 nginx
# Map to specific interface
docker run -d -p 127.0.0.1:8080:80 nginx # Only localhost
# Random host port
docker run -d -p 80 nginx
docker port <container> # See assigned port
# Multiple ports
docker run -d -p 80:80 -p 443:443 nginx
# UDP
docker run -d -p 53:53/udp dns-serverMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Docker Compose Networking
services:
frontend:
image: my-frontend
ports:
- "3000:3000" # Exposed to host
networks:
- frontend-net
api:
image: my-api
expose:
- "8080" # Only internal, not to host
networks:
- frontend-net
- backend-net
postgres:
image: postgres:16
networks:
- backend-net # Not reachable from frontend
redis:
image: redis:7
networks:
- backend-net
networks:
frontend-net:
backend-net:
internal: true # No external accessIn this setup:
- frontend can reach api (both on frontend-net)
- api can reach postgres and redis (all on backend-net)
- frontend cannot reach postgres directly
- postgres cannot reach the internet (internal: true)
DNS Resolution
# Containers resolve each other by name on user-defined networks
docker exec api nslookup web
# Server: 127.0.0.11 (Docker's embedded DNS)
# Name: web
# Address: 172.18.0.2
# Service aliases
docker run -d --name db --network app-net --network-alias database postgres
# Both "db" and "database" resolve to this containerHost Network
Container shares the host's network namespace:
docker run -d --network host nginx
# Nginx listens on host's port 80 directly
# No port mapping needed
# No network isolationUse when: - Maximum network performance needed - Container needs to see all host traffic - Running network monitoring tools
Network Inspection and Debugging
# Inspect network
docker network inspect app-net
# Check container's networks
docker inspect api --format '{{json .NetworkSettings.Networks}}' | jq
# Test connectivity
docker exec api ping web
docker exec api curl http://web:8080/health
docker exec api nslookup postgres
# View port mappings
docker port my-container
# Network traffic
docker run --rm --net container:api nicolaka/netshoot tcpdump -i eth0Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Connect/Disconnect Networks
# Connect running container to a network
docker network connect backend-net api
# Disconnect
docker network disconnect frontend-net api
# Container on multiple networks
docker run -d --name api \
--network frontend-net \
my-api
docker network connect backend-net apiIP Address Management
# Create network with custom subnet
docker network create \
--subnet 10.10.0.0/24 \
--gateway 10.10.0.1 \
custom-net
# Assign static IP
docker run -d --name db \
--network custom-net \
--ip 10.10.0.100 \
postgresCommon Issues
| Issue | Cause | Fix |
|---|---|---|
| Container can't resolve name | Default bridge (no DNS) | Use user-defined network |
| Port already in use | Host port conflict | Change -p mapping |
| Can't reach container from host | No port mapping | Add -p host:container |
| Containers can't communicate | Different networks | Connect to same network |
| Slow DNS resolution | Docker DNS timeout | Check /etc/resolv.conf in container |
| Connection refused | Service not listening on 0.0.0.0 | App binds to localhost, not 0.0.0.0 |
The last one is the most common mistake:
// ❌ Only accessible from inside container
app.listen(3000, '127.0.0.1')
// ✅ Accessible from other containers and host
app.listen(3000, '0.0.0.0')What's Next?
Our Docker Fundamentals course covers networking, compose, and production deployment patterns. Node.js REST APIs teaches containerized API development. First lessons are free.
---
Ready to go deeper? Check out our hands-on course: Docker Fundamentals — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Docker Volumes and Persistent Data
Manage persistent data in Docker with named volumes and bind mounts. Backup strategies, restore procedures, and container data sharing.
Docker Tutorial for Beginners 2026
Complete Docker tutorial for beginners. Learn containers, images, Dockerfiles, volumes, networking, and Docker Compose step by step.
Podman vs Docker Comparison 2026
Podman vs Docker in 2026: rootless containers, daemonless architecture, native pod support, and when to choose each runtime.
Docker Secrets Management Guide
Handle Docker secrets safely. Environment variables, Swarm secrets, mounted config files, build secrets, and Vault integration patterns.
Domain-Specific AI Models Guide
Build and deploy domain-specific AI models with fine-tuning, RAG, and specialized training data for healthcare, finance, and DevOps applications.
Earthly Reproducible Build Tool
Earthly combines Dockerfiles and Makefiles into reproducible, containerized builds. Learn how Earthly works, how to write Earthfiles, and when it replaces.
Explore topics
Browse more articles on the topics covered here.