firewall

  1. pve firewall

    I am completely lost with the firewall configuration on two Hetzner nodes, each with proxmox 6.3-1 and pve-firewall 4.1-3. Let's call them node1 and node2. On both nodes Datacenter Firewall is enabled with ebtables=yes, input policy=DROP, Output policy=ACCEPT and no rules. On node 2 there is a...
  2. nftables interface not available at boot?

    I'm using nftables to implement firewall rules. I have some rules which I need to apply to vmbr1 and the fwbr interfaces. I create my test config file thus: #!/usr/sbin/nft -f flush ruleset table netdev filterearly { chain ingress { type filter hook ingress device...
  3. [SOLVED] Fans ramp up on bridge network

    I am using proxmox 6.3-3 as main vm host. I am hosting my firewall in it. The problem is when I am doing network bonding on my nas server (bsd) the proxmox host fans ramp up and it is roaring until I shutdown/restart the nas box. So my current desktop I tried same network bonding and same thing...
  4. Root Server with Proxmox behind virtualized FW

    Hello everyone, I know there are already many threads on this topic, but so far nobody has helped me. My structure looks as follows: Rented root server at Hetner with fixed ipv4 and an additionally booked ipv4. On the Proxmox runs an OPNsense firewall. All VMs hang in the LAN behind the...
  5. [TUTORIAL] Aussperrschutz, wenn man an der Proxmox Firewall (iptables) rumschraubt

    Wer kennt das nicht, man will die PVE Kiste securen und erstellt Rules in den iptables. Plötzlich hat man sich selber ausgesperrt. Ärgerlich und kann dann nur noch mittels Rescuemodus behoben werden. Bei grossen Kisten mit vielen VMs ist das nicht sonderlich toll. Habe mir ein Script...
  6. [SOLVED] Firewall GUI rule activation

    When adding firewall rules via die GUI, does one have to activate the rules from the command line? How are the rules loaded/activated otherwise?
  7. Firewall rules number column not wide enough and cannot be resized

    When 10 or more rules are created, the column width for the rule number is not wide enough to display the full number and it cannot be resized the way other columns can. Can this be remedied please?
  8. [SOLVED] Ubuntu KVM VPS: iptables --ctstate RELATED,ESTABLISHED rule is broken; working on DigitalOcean but not in Proxmox

    2020-09-22: SOLVED: #5 2020-09-21: Anybody here (at forums.proxmox.com) have a take on this? https://www.reddit.com/r/linuxadmin/comments/ixeky1/ubuntu_kvm_vps_iptables_ctstate/
  9. pve-firewall vs iptables/systemctl reporting discrepencies

    Proxmox newbie here. In my PVE server... 1. If the pve-firewall is running (with policy_in: DROP like it says below, why does iptables report no rules (ie: everything is "accepted")? 2. what does 'disabled' mean in pve-firewall status = disabled/running? (systemctl status pve-firewall.service...
  10. Strange Firewall/ipsec behaviour after upgrading to 6.2-11

    I have recently updated a cluster with a few nodes having pretty similar network setup. Each node is connected with a few external networks over ipsec. And just one node behaves crazy (this is really strange). I can't ping any of the networks that are tunneled through the ipsec. Tunnels are...
  11. taich

    poxmox firewall

    Hi, can you tell me what ports need to be open on a public IP to reach proxmox virtual environment manager? https, 8006? anything else? Thanks for your help.
  12. Inbound internet traffic being dropped

    Hey, I have a VM with Nginx on it that I'm trying to test with and although everything else is working, I can see in the VM firewall logs within the Proxmox console that all the traffic from the internet is dropped. The port forwarding on my router is fine and working as I can see the traffic...
  13. [SOLVED] Weird issue when virtualizing pfSense on Proxmox VE

    I decided to try and virtualize pfsense because sometimes you don't have a spare bare metal hardware to dedicate to it or you do but it's just not worth it for the little amount of resources that pfsense needs (in small to medium networks). Everything works fine except for one weird issue that...
  14. Route all VMs through a firewall VM - confused about bridges

    I want all my VMs to go through my firewall VM. I know I need to bridge all of them but when I check the network on the host it shows the pve IP I chose during install. Do I need to add a new Linux Bridge for every VM or just use the same vmbr0 for all of them and proxmox will do the rest and...
  15. firewall rules not working

    Hey all, I'm setting up a lab with a Proxmox/ceph 3 node cluster. WAN is being provided by a pfsense VM on a different PVE (running multiple pfsense instances for different uses) where the rules are set to block all traffic in the lab LAN except for a specific range of management IP addresses...
  16. [SOLVED] Is there a recommended way to restrict IP addresses to VMs?

    How do you restrict (KVM) VMs to only use their assigned IPv4 and IPv6 addresses? I'm looking for something like filtering IPs by MAC addresses (for ex. via ebtables). Is there support for something like that built into Proxmox? What is the recommend way? I can't be the only one who would need that.
  17. How to get better performance with pfsense vm

    i've seen many posts regarding this topic but thought i'd add one more about pfsense performance under prox. I'm new to proxmox but I think it's been really great solution so far. I had both pfsense and opnsense running to compare the 2. I was super excited when i fired up the vm and ran...
  18. open port on windows VM

    Hello, I have a dedicated server with ProxMoX with one Windows Server VM inside it with a public IP. Inside VM the port 1433 is open but it's filtered from node. Firewall in ProxMoX (Datacenter, node, VM0 is disabled. nmap 1.1.1.1 -p1433 Starting Nmap 6.40 ( http://nmap.org ) at 2020-08-12...
  19. Access to Other VM/CT via cURL

    Hi, I get a "timeout" when I try to access other guests via Proxmox Shell via cURL. There is no extra obstacle or command in the firewall. However, access is timing out. What could be the reason for this and how can I turn on port access? Proxmox 5.4-3 root@compute-ua:~# curl...
  20. Irrelevant packets as present for every VM on proxmox-host

    My network has some issues. When the network traffic increases, the network connections tend to be very slow even though it's an 10GB network. I'm not sure whether it's proxmox-related or not. Example: VMx = virtual machine x VHx = proxmox virtual host x VM1 = 192.168.0.51 (E2:A9:CC:75:79:AF)...

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get your own in 60 seconds.

Buy now!