The server has an additional IP address from the hosting provider. I already added all the rules normally. However currently the second IP can be used to connect to docker services. Adding a rule to block without "route" to the secondary address blocks things outside of docker like ssh, but with "route" it does not work. It's like either both or none. Does anyone have a solution or at least have an explanation?