Search results

  1. E

    nftables in production

    It does not work for me. Pretty common firewall rules are not working, so I just disabled the firewall for now.
  2. E

    Blocking LAN access for VMs does not work accept ping using nftables.

    Any update on this, my rules are still not working! Pretty common rules Allow fd88::1 Allow 10.88.88.1 Reject fd88::/64 Reject 10.88.88.0/24 It used to work in iptables but not in nftables. Pinging out from VM correctly blocks IPv4 ping but not IPv6 ping. Cannot connect to any VMs that has the...
  3. E

    nftables: no stateful rule for output

    It used to work with iptables but not with the new nftables. I am not sure about creating new rules in nftables.
  4. E

    nftables: no stateful rule for output

    I have a similar problem https://forum.proxmox.com/threads/blocking-lan-access-for-vms-does-not-work-accept-ping-using-nftables.145748/ Pretty common and basic firewall rule. Allow gateway and block LAN, IPv4 is somewhat working IPv6 not at all.
  5. E

    Blocking LAN access for VMs does not work accept ping using nftables.

    Same rules worked fine with iptables. Now I cannot connect to any of the VMs using SSH. Pinging fd88::7 should be blocked from VMs but is allowing outbound connection while pinging 10.88.88.7 correctly blocks outgoing ping. I allowed IPv6 and IPv4 router gateway in the rules. cat...
  6. E

    Blocking LAN access for VMs does not work accept ping using nftables.

    Looks like I need ct state established,related accept in my VM config. chain guest-100-in { jump allow-dhcp-in jump allow-ndp-in ether type arp accept jump group-block-lan-in jump after-vm-in...
  7. E

    Blocking LAN access for VMs does not work accept ping using nftables.

    I could not get the new firewall to work, disabled it for now. Looks like IPv4 is somewhat working and IPv6 rules are not working at all for VMs.
  8. E

    Blocking LAN access for VMs does not work accept ping using nftables.

    I used to block private range 10.0.0.0 from the firewall and allowed the gateway and it worked but now after upgrading and enabling nftables I can ping VMs but they will not connect using any other port (SSH, HTTPS). Once I disable outbound rule blocking 10.0.0.0 I can connect to all the VMs in...
  9. E

    How do I enable and use nftables?

    How do I enable the nftables and start playing with it, I just upgraded to 8.2 Update: Found it in Datacenter > Node > Firewall > Options > nftables > enable.
  10. E

    Can´t access to Proxmox web console using port 443

    Why dont you change port in proxmox interfaces file. post-up iptables -t nat -A PREROUTING -p tcp -d 192.168.1.10 --dport 443 -j REDIRECT --to-ports 8006 https://saudiqbal.github.io/Proxmox/proxmox-IPv6-interface-setup-DHCPv6-or-static.html
  11. E

    Firewall rule Ipv6

    I have the same setup as yours but mine is blocked, maybe try fc00::/7 instead of fd00::/8
  12. E

    Firewall rule Ipv6

    If you want to block all local IPv6 use fd00::/8 and REJECT
  13. E

    Firewall rule Ipv6

    I am already doing it with my Proxmox https://www.reddit.com/r/Proxmox/comments/rm2bw4/firewall_how_to_block_all_traffic_to_local_network/ See the screenshot in that post.
  14. E

    IPv6 SLAAC (autoconfig) for "management" only ?

    You are right about using iface vmbr0 inet6 auto in your interface file and you have to accept RA net.ipv6.conf.vmbr0.accept_ra=2 in your sysctl.conf file I wrote a blog post for using IPv6 in Proxmox. https://saudiqbal.github.io/Proxmox/proxmox-IPv6-interface-setup-DHCPv6-or-static.html
  15. E

    Is it possible to get a short summary in notifications instead of every detail?

    Is it possible to get Gotify and Email notifications with just a summary instead of every detail in notifications. For example New software packages available with a full table of updates. Backup notifications includes all the progress percentage from 0% to 100% Long list of progress. Just a...
  16. E

    Package update notifs not working

    I have the same problem with gotify. I used the command above and see if it works.
  17. E

    Is ProxMox doing anything after VMware disaster?

    Why not make your partner in North America a dedicated support instead of calling them partners, this will work with enterprise customers. I am just a home user and saw ProxMox losing big paying customers on reddit and other forums.
  18. E

    Is ProxMox doing anything after VMware disaster?

    https://www.reddit.com/r/Proxmox/comments/19fjyqf/any_official_word_from_proxmox_since_vmware/ This is why ProxMox need North America support ASAP before companies move to another solution, they will never come back once they go elsewhere. Proxmox have to move fast.
  19. E

    Is ProxMox doing anything after VMware disaster?

    In that thread "and is closing that gap in the Americas too" is a news but ProxMox should not wait too long, time is now for 24/7 American support before any missed opportunity and missed customers for ProxMox.

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!