firewall

  1. N

    No connection NFS on Synology

    I am running a synology NAS on 192.168.0.100 with NFS activated. Share "proxmox" has been set on synology with user rights R/W. It is visible to * with NFSv4.1 active. (I have tried 3.0 before, same results) The NFS Share can be found and accessed from local Mac computers. Any help is...
  2. H

    No WebGUI or ssh into PVE, but ping works; Everything works from phone though?

    Hi there! I'm running into a really wild issue here: I want to access my PVE remotely from a different network, so I'm using a wireguard VPN running in an LXC on my Proxmox node. I can use it and ssh into it and other LXCs just fine, however I can't access the pve itself neither by ssh nor by...
  3. D

    Firewall questions

    Proxmox 8.1.3 - So we have a firewall at the Datacenter, Node and VM level. I want to add a rule so that all VMs cannot access a computer (not on Proxmox) on a specific IP addresses. Do I need to add the DROP rule on each VM or can I put one DROP rule at the Node level? On a firewall rule, if I...
  4. J

    HTTPS macro includes UDP?

    Hey everyone! Quick question: Does the HTTPS macro of the PVE Firewall include UDP traffic (to port 443) or is it still just TCP? I am on PVE 7.4-17, but if it is available in PVE 8.x I would also be interested in the answer, since I plan on migrate to it soon. Thanks in advance.
  5. I

    Dual Proxmox + Dual Firewall Setup

    Hi All, I would like to implement the following. I've been fighting the whole weekend to set this up, with no success so far. Initially, I wanted to use Sophos XG as my Firewall, but I reverted back to Pfsense for now as it seems easier to configure for a noob like me. On my...
  6. E

    Make Two different Proxmox Lan's VMs to communicate with each other.

    I currently have two proxmox Metals in Scaleway Cloud. Yesterday I bought my second one but with the first one I didn't have any issue. So my setup in the first one is a pfsense firewall with a WAN and a LAN in 192.168.1.0/24. Now I introduced the second Metal and created another pfsense (I know...
  7. H

    SSH connection between VM's accross different VLAN's while using Firewall

    Hi, I read over some other threads that this issue is known but the solution does not seem to be official. That's why I'm posting this one. Example: VM1 on vlan30 and VM2 on vlan60 - VM1 can ping VM2 (and vice versa) - VM2 cannot ssh VM1... But VM1 can ssh to VM2 - PVE firewall is activated...
  8. G

    Firewall, migrations/SSH for ringX addresses when output is filtered?

    Hi, I noticed that if I set the OUTPUT policy to DROP, I need to add a few rules by default for SSH, migrations to work if I add another ringX address. Could it be that some rules that gets set by default for INPUT may have been forgotten in output ? I see the usual ports...
  9. W

    Permanent local firewall configuration

    Hi To avoid to loose emails during patches and upgrades we usually closed the SMTP ports via the local firewall in the past at other Linux mail relays. Now I'm missing the functionality of iptables-save / iptables-restore at the PMG. Even after installing the mentioned packages and saving the...
  10. D

    [SOLVED] LXC-Firewall hat keinen Effekt

    Hi, Ich versuche die outgoing connections eines LXC derart zu unterbinden, dass er nur noch auf einen bestimmten Host auf zwei bestimmten Ports zugreifen kann. LXC1 -------------------tcp 1883/8883--------------->LXC2 Dazu habe ich Firewall im Datacenter aktiviert Firewall der Node auf...
  11. I

    TCP RST packets dropped by PVE Firewall

    I'm running into exactly the same issue as #56300. The previous thread was old and I have more details on that, so I thought I'd just open a new thread. PVE version is almost up-to-date: proxmox-ve: 8.0.2 (running kernel: 6.2.16-6-pve) VM → Firewall → Options → Firewall = No: No effect VM →...
  12. G

    [SOLVED] Can't drop Anydesk discovery multicast traffic at node or cluster level

    Hi, PVE 7.4-16 here. It looks like I can't drop this type of traffic at datacenter/node level. Only VM level works. As per Anydesk documentation (and further traffic sniffing) this is the traffic I need to drop: - protocol: UDP - destination IP: 239.255.102.18 (multicast) - destination ports...
  13. N

    Proxmox VE firewall not blocking SSH

    I have a very strict firewall policy that essentially boils down to, block ALL traffic from any and all servers and computers that are not essential to that host's operation or needs. This seemed fine for a while but I just realized that anything on VLAN 10 can access Proxmox via SSH, even...
  14. S

    Proxmox with a Separate Host Running OpnSense in Hetzner

    Hi all, I'm working on my first setup at Hetzner and I can't find any examples of what I am attempting to do. I'm hoping for some insight, an interfaces config or step by step if it's available would both be very helpful! While there's plenty of instructions with regard to hosting OpnSense...
  15. M

    Firewall is not working at cluster and node level

    Hi guys, I am using Proxmox 8.0.4 and really enjoying it so far. I tried to set up the firewall at the cluster level and the node level, but it doesn't work except at the VM/container level. Whatever rules I make, I can bypass them like they didn't even exist This is what I did: 1. After and...
  16. H

    IPSet not applying as expected / Alias alone working however

    Hi everyone, I am trying to grant access to the Proxmox node via SSH based on some ACCEPT firewall rules on the node level on this single host setup. What already worked have been the following two rules referencing previously defined Aliases: Aliases: FW-Rules: Since this looked like a...
  17. H

    I don't understand what Firewall:Yes does on virtual machine?

    Hello everyone, I have 2 security groups. One is applied to the datacenter and allows port 22 access. Another is applied to the virtual machine and allows VPN access. This works fine as far as I can tell. However, today I found the setting, under a virtual machine => Firewall => Options =>...
  18. K

    Why is my PVE IP showing in firewall logs when I attempt to join from a public IP ?

    Hello, I'm quite new to Proxmox and there is something I don't get. I've just done some firewall rules (filtering public IPs who can access a specific VM on specifics ports). But when I attempt to test unauthorized IPs, I can access my resources (which isn't supposed to be normal). When I see...
  19. Y

    Proxmox ignores Firewalling on interface at host level, but accepts at vm level.

    hi, i have a proxmox setup (7.4-3) with 2 seperate physical interfaces. both are conennected to the same LAN segment (192.168.1.0/24). one is bridged to vmbr0 (managment of the host itself) and proxmox has an IP address on that interface. the other network adapter is a usb adapter (bound to...
  20. H

    Help understanding default firewall rules

    Hello everyone, I'm trying to setup proxmox firewall for the first time. I've used ufw, csf, firewalld prior...seems like having an integrated solution would be nice and my rules aren't super complicated.I was planning on setting up some security groups and applying them. My main confusion...

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!