Smart?

Whats the question?
Why don't they at least default port 8006 open when you turn the firewall on the data center.

I figured it out.
To everyone else, add this to the firewall rules before turning the datacenter firewall on or you will lock yourself out of Proxmox host if your are remote.

1714356415386.png

1714356550190.png
 
Why don't they at least default port 8006 open when you turn the firewall on the data center.
It's already open by default, so you can enable the firewall even with with "input policy" set to "DROP" or "REJECT". You only need manually to open that port in case you create a rule that explicitely blocks it, as custom rules got higher priority than the input/output policies or hidden default rules. See the hidden anti-lockout rules: https://pve.proxmox.com/wiki/Firewall#pve_firewall_default_rules
 
Last edited:
It's already open by default, so you can enable the firewall even with with "input policy" set to "DROP" or "REJECT". You only need manually to open that port in case you create a rule that explicitely blocks it, as custom rules got hogher priority than the input/output policies or hidden default rules. See the hidden anti-lockout rules: https://pve.proxmox.com/wiki/Firewall#pve_firewall_default_rules
Not true, i turned mine on the "datacenter", not the master and it locked me out until i added those rules. I had to get with the NOC to shut the firewall back off.

That is what I wanted, all traffic blocked to my master except me. No big deal, water under the bridge. Yes all traffic to it is dropped unless allowed through. Why would you have your master open to the world anyways?

1714360843210.png
1714360993374.png
 
Maybe both is correct: after enabling the datacenter "main switch" for the firewall I still can connect to the nodes via 8006 - from the same LAN. My admin-workstation is in another local network and access from there fails.

The lockout-prevention rules are focusing the local network access...
 
  • Like
Reactions: _gabriel and Dunuin

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!