PVE Firewall on Proxmox 8.1+ Does not seem to be working properly. Is it something I've missed?

ArcticLime

New Member
Jan 29, 2024
2
0
1
Hello everyone, good day.

Thank you for your time in advance.

I'm new with Proxmox, I've recently re-created my environment since I've gotten rid my ESXi environment. So I'm learning as I go. (really love this product.)
I've just installed ProxmoxVE fresh of the ISO. Its a blank canvas so far.

I've reviewed the following forum posts and also tutorials to get better acclimated with how the firewall functions:

Link1

Link2

Everything up to now works phenomenally well. with an the exception of the firewall. Which I'm not sure if its an issue I've done or it might indeed be an issue with the firewall itself. So any help is greatly appreciated.

This is what I'm trying to do:

I want to implement the Firewall on a VM (IP: x.x.x.105) to only allow traffic from the internal proxy (x.x.x.102) I have to the destination port:8080.

So far based on the information I've gathered from the links above. This is what I've setup so far.


1. Enabled Firewall on the Cluster itself.
firefox_xaQedDrcIe.png

2. Made sure the firewall was enabled on the Node itself (Check)

3. Enabled the Firewall on the VM itself:

firefox_glR34zNckY.png

4. Made sure to enable the Firewall on the net0 interface in the 'Hardware' Tab of the VM to start the firewall
firefox_55FkOEu2Py.png

Once this was enabled I tested it to make sure no traffic was able to access the and it worked properly. Which it did not so that was the intended behavior.

5. Then I created this rule: To only allow traffic to port 8080 via tcp from the proxy 'reverse' (x.x.x.102) to the 'test' vm (x.x.x.105)
firefox_VZTfG5vsqF.png


The issue I seem to be facing is that; once I attempt to test it, all traffic from the same subnet seems to be able to reach 'test' via direct IP (x.x.x.105) as well. VS what was the goal was which is to only allow that traffic from the proxy only via port 8080?

Did I miss something? What did I do wrong? Did I create the rules incorrectly? Any help will be greatly appreciated.

Thank you for your time.
 

Attachments

  • firefox_glR34zNckY.png
    firefox_glR34zNckY.png
    22.8 KB · Views: 4
  • firefox_OunuTXQEOF.png
    firefox_OunuTXQEOF.png
    30.4 KB · Views: 4
Never-mind, I found out the issue. I've been creating Aliases of devices with the /CIDR notation which seems to be for network aliases.

Thanks for reading.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!