firewall

  1. B

    Proxmox absichern

    Hallo Liebe Proxmox Community, Aktuell bin ich in der Einrichtung eines Proxmox Servers, darauf laufen 2 VM´s mit Windows 10. Das Web Interface von Proxmox ist nur im internen Netzwerk erreichbar. Auch weiter noch nichts konfiguriert oder vorgesehen. Meine Frage ist nun: Muss ich noch etwas...
  2. S

    Use PVE node's external IP address to reach service of a internal network via DNAT

    Hi everybody, I am struggeling with a problem where I did not figure out yet if it is a "basic" networking problem or something that has to do with my SDN configuration. The setup is the following: I have two VEs (192.168.2.10 and .11) coupled as a cluster. Within this cluster there is an...
  3. DynFi User

    [TUTORIAL] Installing an Open Source Firewall on Proxmox-VE 7.3

    DynFi company is a Proxmox-VE partner and also the developer of the DynFi Firewall, a new, modern Open Source Firewall. Since Proxmox-VE and DynFi Firewall are very complementary, we thought that It would be nice to provide end-users with a Screencast detailing the steps required to create a...
  4. S

    Fresh VyOS routing setup - consistent drop of packets (100%), but only some applications

    Hi guys, We need some help please. In short - we've setup vyos routing on our pve cluster. The problem is as soon as vyos vm get's an IP address and starts peering all the other guests on the SAME host with firewall ON (on the nic), SOME applications (curl and rsync - there might be more, but...
  5. M

    Port Fowarding

    I am trying to port foward HTTP:80 to IP: 24.12.3.250 I can access my website from 24.12.4.250 since it on the internal network shown below, but when its time to access it from outside the private network I can't access it. (The unnamed router at the top is my home network with the subnet...
  6. N

    [SOLVED] [FAILED] Failed to start LSB: Personal Firewall

    Hello, I have been using PVE for several months and recently I had to change my motherboard, after replacing the motherboard of my server I have a defect when starting the promox distribution: [FAILED] Failed to start LSB: Personal Firewall :mad: In front of my server I use a netgate...
  7. M

    status update error: iptables_restore_cmdlist

    I don't know when this issue started, but I have IPv6 disabled via grub by using "ipv6.disable=1" on GRUB_CMDLINE_LINUX_DEFAULT in /etc/default/grub. My syslog is being flooded with the following messages: Nov 19 10:53:24 pve pve-firewall[1053]: status update error: iptables_restore_cmdlist...
  8. M

    PVEFW NFLOG with custom rules

    Hi, I have created my own LOG chains for specific rules added for each guest. My first question is how can I log in separate log file like PVEFW does per guest? Currently all logs go into the Node's firewall log. Second question is, how can I format the log output to be similar to PVEFW? At...
  9. J

    How to configure the firewall of an LXC via Ansible module proxmox?

    Good day everyone! I am trying to provision some LXC in my 4-node Proxmox 7.2 cluster via Ansible using the proxmox module. After much struggle I've been able to provision the container but I am stuck at the firewall configuration. Currently I am trying to template a firewall.j2 file into a...
  10. M

    Guest iptables rules

    I`m trying to add some custom iptables rules (like connlimit) for guest machines. Example rule is: -A tap101i0-IN -p tcp -m connlimit --connlimit-above 30 --connlimit-mask 32 --connlimit-saddr -j REJECT --reject-with tcp-reset As seen tap101i0 is the vm 101 adapter. The rule has no effect, I...
  11. E

    Proxmox Host and ufw firewall

    Hi I try to understand how a proxmox host can be hardened with ufw. I understand that proxmox has a own firewall but I have an ansible role which manage hardening etc. on all my servers and therefore would like to use ufw on my proxmox host. However as I tried to use I saw that my lxc...
  12. M

    [SOLVED] Firewall blocks traffic between VMs on same host and in different VLANs

    Hi, I was trying to use Promox firewall but ran into "strange" problems: as soon as firewall on DC level (but not on VM level!!) is active real traffic between VMS running on the same host, but in different VLANs, doesn't work. I emphasize "real traffic" because ping still works and also a...
  13. E

    [SOLVED] Proxmox Windows VM Outgoing Network

    Hi, I'm new around here and trying to learn Proxmox. I installed Proxmox on Linux. Everything is very good. In it, I installed Windows Server 2022, as a VM. Normally all ports are closed when I activate the firewall. I open the necessary ports for 8006 and RDP, no problem. The problem also...
  14. Y

    VMs do not seem to get IP from DHCP

    I just created two VMs and for some reason they don't seem to get IP assigned from the DHCP server. When I give them static IP it does work. I just go into Proxmox fyi. So there must've been something I missed configured or haven't configured at all. Thank you.
  15. S

    Firewall - Internet Speed

    Hey everyone, We have a 10G Internet connection but we are not even reaching 1GB Internet Speed to the firewall installed on proxmox. We have used the Intel1000 as nwetowrk card. Is it possible to get the full Internect connection speed to the firewall?
  16. G

    [SOLVED] No internet on network

    Hello. I want to give internet access to a VM. I used this technique a lot of times, why is now not working? # network interface settings; autogenerated # Please do NOT modify this file directly, unless you know what # you're doing. # # If you want to manage parts of the network configuration...
  17. G

    persistent nf_conntrack sysctl

    Hello. I am trying to modify nf_conntrack options in /etc/sysctl.conf i have : net.netfilter.nf_conntrack_generic_timeout=60 net.netfilter.nf_conntrack_icmp_timeout=10 #net.netfilter.nf_conntrack_tcp_timeout_close=10 net.netfilter.nf_conntrack_tcp_timeout_close_wait=20...
  18. R

    Enabling firewall breaks VPN

    Hi, We've been looking into enabling firewall on our PVE. A VM is running Windows serving Microsoft AlwaysOn IKEv2 to clients. When firewall is enabled on the cluster, the clients are no longer able to authenticate, existing connections continues to function, until they disconnect. As soon as...
  19. J

    Network Namespace not working with PVE Firewall

    Hello! In a VM I created a network namespace "ns_twsgw" (IP a.b.c.82, main IP a.b.c.81) with a bridged macvlan (second MAC address on the virtual ETH IF). I see all the ping packets from the "ns_twsgw" network inside the VM with tcpdump, but I don't see them on the bridge IF (e.g.: fwpr106p0)...
  20. S

    VM Ports blocked from local network but not from Proxmox host

    I've been having an issue where various VMs become spontaneously unreachable from local machines, but are still reachable from proxmox itself. I don't have any firewall turned on in proxmox or the VMs, but it's acting as if there is one. I can't make heads or tails of this -- it just starts on...