proxwolfe's latest activity

  • P
    I use headscale, too. But establishing a common network between my otherwise segregated PVEs means to circumvent my inner firewall. If I were willing to do this, it would easier to remove the firewall instead of making an effort to circumvent...
  • P
    Yes, that would work, if both PVEs shared the same management network. But they don't. The networks outside my inner firewall and inside are totally segregated. Nothing goes in. That's the problem in my case. And, yes, I could put them on the...
  • P
    Okay, so set up a tailscale network for example. That is an option, but my objective is to let nothing from the outside reach behind my inner firewall. And having a common network between inside and outside would basically circumvent the inner...
  • P
    I'm aiming for maximum security. But, admittedly, I'm still learning. How so? The PVE management network is, of course, separate from the DMZ network. That is, actually, the contingency, I'm trying to provide for. Well, there is the obvious...
  • P
    Yes, I believe that is a classic setup. And yes, there are two fully fledged firewalls. One on the edge to the internet and one behind it at the edge of my private LAN. It does seem so. Unless, of course, Proxmox take up my suggestion to have...
  • P
    Only the VMs live in the DMZ. The PVE that serves them does not. The PVE management interface, of course, is on a separate management network and not reachable from the DMZ.
  • P
    Up to now, it has been my policy to not allow anything from the outside into my inner firewall. Ideally, I would like to keep it that way. If no viable other solutions exist, port forwarding would indeed be an easy option. But how would I...
  • P
    Up to now, it has been my policy to not allow anything from the outside into my inner firewall. Ideally, I would like to keep it that way. If no viable other solutions exist, wireguard certainly would be an option. And how would I use that to...
  • P
    In my homelab I have a small cluster from which I serve some applications that live in my DMZ. And I have another node inside my inner firewall on which I run some apps that need not be reachable from the public internet. Amongs others, I run PDM...
  • P
    This did the trick. Thank you.
  • P
    Hi, I have a PBS running for a while without any issues. My PVE cluster is doing regular backups to the PBS. Today, I changed the PBS's name (and FQDN). Of course, under the new name (and the new FQDN) it can't be accessed anymore by PVE. So...