firewall

  1. T

    [SOLVED] I've error kernel: nf_conntrack: nf_conntrack: table full, dropping packet in syslog.

    Hello, I found message " kernel: nf_conntrack: nf_conntrack: table full, dropping packet " in syslog. and I have increase value nf_contrack but still show the message. Could you please suggest for check the problem. Best regards,
  2. B

    Problems with Host Firewall

    I have a host I am trying to enact the firewall on. It has a server running apache on ports 80, 443. I have tried many things to get a reaction from the firewall. Logging doesn't show anything for the host level and output from iptables -L doesn't show my firewall rules. What am I missing? I...
  3. H

    custom pre/post-scripts/hooks for ACME renewals (not plugins, but firewall etc. related)

    I'm in need of executing a script to allow traffic through firewall and open port 80 inbound to the PVE (and next PBS), and then once done, close the ports etc. Is there a current way to do it in PVE 7.x ?
  4. M

    Proxmox VE 8 with Firewall in Routed Configuration. Netfilter POSTROUTING SNAT not working

    Hi, since switching to Proxmox VE 8 Postrouting SNAT (Unfortunately I must use NAT) in combination with the Proxmox Firewall is not working anymore even with conntrack zones enabled. In Proxmox VE 7 it worked after adding post-up iptables -t raw -I PREROUTING -i fwbr+ -j CT --zone 1...
  5. rian81

    [SOLVED] VM Firewall didn't working after install qemu-guest-agent on vm

    Hi, I have a strange case. I had set firewall on VM level, and the rule on firewall running well as I want. But after install qemu-agent-guest and enable qemu-agent. The firewall rule didn't running well like before install qemu-agent-guest. I work with pve 7.4-13 Thanks
  6. S

    SSH Firewall rule does not work on server machine

    I enabled firewall on Datacenter, node and some VMs. Ping works but strange. If I start ping and disable rule during it pinging, it continues ping. If I stop ping and try again then it is not working. But that is not an issue for me. I can access my host machine with SSH no matter wat. I...
  7. D

    Enabling Firewall breaks connection to all VMs

    Hello, I have a proxmox server running 7.4-13. When I try to enable the firewall on datacenter level, all connections to my VMs break and I can't ping them. Even those VMs which have no firewall enabled in VM Firewall and Hardware settings. Also my NFS mount from my TrueNAS VM breaks...
  8. T

    Proxmox host can't reach the Internet - VM Firewall/gateway scenario

    Hi everyone, After a couple of days of struggling, reading the Internet, and watching tutorials on YT, I still couldn't figure out how to give Proxmox host access to the Internet via Gateway/Firewall guest. Please advise if this is even possible and/or where the problem is. Some info about the...
  9. T

    Proxmox Firewall Doesn't seem to work and errors in log

    I'm trying to start making use of the Proxmox Firewall at Node/VM/NIC level. I've enabled the firewall at datacenter and node level initially, but the rules I've put in place don't seem to take effect, and I'm also getting these lines repeatedly in my PVE logs: Jun 03 12:32:57 pve...
  10. N

    [SOLVED] WebUI PAM Zugang Einschränken / WebUI restrict PAM (root) Login

    Hallo zusammen, Ich möchte die WebUI über VPN für andere Erreichbar machen, damit diese Ihre VMs selbst verwalten können. Nun hab ich mir die Frage gestellt, ob es denn möglich ist den Root Zugriff auf die WebUI nur in einem bestimmten Netzwerk zuzulassen? Heimnetz: Root kann sich anmelden...
  11. S

    Arma 3 Server

    Hello! I'm trying to make an arma3 server that runs on proxmox on a windows VM. The server seams to be running in it's console, however the server does not show up on the server list. I have opened ports in the VMs firewall, however I am struggeling to open them in proxmox itself. The port I...
  12. C

    cluster.fw not inside /etc/pve/firewall ?

    Hello, I was following a video named "Proxmox VE Full Course: Class 11 - Integrated Firewall" in which the teacher was showing the location of the cluster.fw file to show its the spot where you would disable the firewall should you get stuck after enabling the firewall and locking yourself...
  13. S

    Firewall still allowing Ping after disabling ICMP rule

    So i'm currently learning proxmox on a mini pc at home, with the intention of deploying on a root server in the future. i was trying out the proxmox firewall function on datacenter and pve1 layer. i have a rule on the datacenter allowing tcp traffic on port 8006 for the web interface, same...
  14. R

    Firewall not working as Expected

    I have enabled Firewall on Datacenter, Node and VM level but it doesnt work fully. I disabled outgoing port 25 on my IP as shown in screenshot below but on port checker online it shows port 25 as open. I cant telnet into it still it shows open. I have enabled incoming macro mail in order for my...
  15. R

    Spam Received even after outgoing port 25 blocked

    Hello my clients are hosting mail servers and I want to block all outgoing emails for all my VM so i made firewall settings, at datacenter level, node level and security group and enabled it for all VMs For Datacenter its as follows For Node Level it is as follows For VM Level it is as...
  16. S

    Proxmox - Externer Zugriff aus dem Internet auf VMs, Firewall und Sicherheit - Fragen

    Hallo Zusammen, ich stehe im Moment total auf dem Schlauch. In großen Netzwerken gibt es in der Regel eine DMZ und in dieser immer eigene Hyper-Visor für spezielle VMs, welche von Extern (aus dem Internet) erreichbar sein sollen. Hier gibt es dann auch meisten größere Firewalls, welche den...
  17. P

    Unable to block 22 and 8006 traffic

    I'm following Jay's proxmox tutorial (https://www.youtube.com/watch?v=DNsLLrCgK0U&list=PLT98CRl2KxKHnlbYhtABg6cF50bYa8Ulo&index=12) and using exactly the same steps I receive different results: after turning on firewall both on datacenter and host level, I am not blocked. Both 8006 and 22 works...
  18. N

    Force all traffic in a bridge through router VM

    I have already searched for similar questions but wasn't able to find a satisfying answer (or maybe I just overlooked it). I have a VM with OPNsense that acts as a central firewall and router, which is connected to vmbr0 (WAN) and vmbr1 (LAN). There are multiple other VMs connected to vmbr1. I...
  19. U

    Unable to access My Proxmox GUI after changing Input Policy from Accept to Drop

    Hello, Please help me solve this issue. I had access to my Proxmox GUI interface. I was setting up firewall to allow a particular IP to access GUI. The only chande i made was to enable firewall and change Input Policy from Accept to Drop. Now i can access the GUI once more. I've try to follow...
  20. R

    Iptables inside LXC container not blocking anything

    I've been hitting my head to the brick wall that is iptables inside a Debian 11.3 container in Proxmox. I cannot seem to get it to block anything and there seems to be some contradicting discussions about if iptables should even work inside LXC. I do use Proxmox firewall as well, and it is...

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!