IP Set

etu

New Member
Mar 14, 2024
17
0
1
I have a problem with IP sets in the Proxmox firewall. When I try to create a group with my three nodes 10.0.90.207,8,9/23, I start with 10.0.90.207/23. However, when I try to add .8/23, it gives me an error saying that the CIDR already exists. Should I enter the IPs without the CIDR?eeee.png
 
the ipset already contains all addresses from 10.0.90.1-10.0.91.254 because of the /23 prefix.. if you want to add individual IPs, then you need to use /32 (for IPv4 :))
 
Okay, I understand. To work around the problem, I created aliases like 10.0.90.208/23, etc., and then I put them into an IP set. So, it will create duplicates. Should I put 10.0.90.208/32, etc., in my aliases and then add them to the IP set ?
 
well, that depends on what the ipset contents should be? do you want to include the whole /23 subnet? then put that in. if you only want to include the three IPs you posted above, then just put those IPs in it (with /32 or no prefix). there is no need for aliases.
 
  • Like
Reactions: etu
ok good
well, that depends on what the ipset contents should be? do you want to include the whole /23 subnet? then put that in. if you only want to include the three IPs you posted above, then just put those IPs in it (with /32 or no prefix). there is no need for aliases.
Great thank you
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!