firewall

  1. M

    PVEFW NFLOG with custom rules

    Hi, I have created my own LOG chains for specific rules added for each guest. My first question is how can I log in separate log file like PVEFW does per guest? Currently all logs go into the Node's firewall log. Second question is, how can I format the log output to be similar to PVEFW? At...
  2. J

    How to configure the firewall of an LXC via Ansible module proxmox?

    Good day everyone! I am trying to provision some LXC in my 4-node Proxmox 7.2 cluster via Ansible using the proxmox module. After much struggle I've been able to provision the container but I am stuck at the firewall configuration. Currently I am trying to template a firewall.j2 file into a...
  3. M

    Guest iptables rules

    I`m trying to add some custom iptables rules (like connlimit) for guest machines. Example rule is: -A tap101i0-IN -p tcp -m connlimit --connlimit-above 30 --connlimit-mask 32 --connlimit-saddr -j REJECT --reject-with tcp-reset As seen tap101i0 is the vm 101 adapter. The rule has no effect, I...
  4. E

    Proxmox Host and ufw firewall

    Hi I try to understand how a proxmox host can be hardened with ufw. I understand that proxmox has a own firewall but I have an ansible role which manage hardening etc. on all my servers and therefore would like to use ufw on my proxmox host. However as I tried to use I saw that my lxc...
  5. M

    [SOLVED] Firewall blocks traffic between VMs on same host and in different VLANs

    Hi, I was trying to use Promox firewall but ran into "strange" problems: as soon as firewall on DC level (but not on VM level!!) is active real traffic between VMS running on the same host, but in different VLANs, doesn't work. I emphasize "real traffic" because ping still works and also a...
  6. E

    [SOLVED] Proxmox Windows VM Outgoing Network

    Hi, I'm new around here and trying to learn Proxmox. I installed Proxmox on Linux. Everything is very good. In it, I installed Windows Server 2022, as a VM. Normally all ports are closed when I activate the firewall. I open the necessary ports for 8006 and RDP, no problem. The problem also...
  7. Y

    VMs do not seem to get IP from DHCP

    I just created two VMs and for some reason they don't seem to get IP assigned from the DHCP server. When I give them static IP it does work. I just go into Proxmox fyi. So there must've been something I missed configured or haven't configured at all. Thank you.
  8. S

    Firewall - Internet Speed

    Hey everyone, We have a 10G Internet connection but we are not even reaching 1GB Internet Speed to the firewall installed on proxmox. We have used the Intel1000 as nwetowrk card. Is it possible to get the full Internect connection speed to the firewall?
  9. G

    [SOLVED] No internet on network

    Hello. I want to give internet access to a VM. I used this technique a lot of times, why is now not working? # network interface settings; autogenerated # Please do NOT modify this file directly, unless you know what # you're doing. # # If you want to manage parts of the network configuration...
  10. G

    persistent nf_conntrack sysctl

    Hello. I am trying to modify nf_conntrack options in /etc/sysctl.conf i have : net.netfilter.nf_conntrack_generic_timeout=60 net.netfilter.nf_conntrack_icmp_timeout=10 #net.netfilter.nf_conntrack_tcp_timeout_close=10 net.netfilter.nf_conntrack_tcp_timeout_close_wait=20...
  11. R

    Enabling firewall breaks VPN

    Hi, We've been looking into enabling firewall on our PVE. A VM is running Windows serving Microsoft AlwaysOn IKEv2 to clients. When firewall is enabled on the cluster, the clients are no longer able to authenticate, existing connections continues to function, until they disconnect. As soon as...
  12. J

    Network Namespace not working with PVE Firewall

    Hello! In a VM I created a network namespace "ns_twsgw" (IP a.b.c.82, main IP a.b.c.81) with a bridged macvlan (second MAC address on the virtual ETH IF). I see all the ping packets from the "ns_twsgw" network inside the VM with tcpdump, but I don't see them on the bridge IF (e.g.: fwpr106p0)...
  13. S

    VM Ports blocked from local network but not from Proxmox host

    I've been having an issue where various VMs become spontaneously unreachable from local machines, but are still reachable from proxmox itself. I don't have any firewall turned on in proxmox or the VMs, but it's acting as if there is one. I can't make heads or tails of this -- it just starts on...
  14. F

    Firewall Input Policy DROP do not work

    Hello, When the Firewall is set on default Input Policy DROP on Datacenter level, and the Firewall is enable, it does not work at all. The server is not filtered and is fully open, just like by ACCEPT. I can easily access it from different PC, without said PC being in rules or Security Group...
  15. P

    Cluster Firewall

    Hi Guys, I have 4 Server cluster i am trying to apply firewall rule to block 1 IP range from another interacting or accessing but i am unable to do so, i have been scratching my head since morning if someone can enlighten me a bit it would be great. firewall is enabled on Datacanter->Node-> VM...
  16. I

    Random unrelated addresses on pvefw logger

    Hi, a security group I set up is blocking and logging some traffic that doesn't make sense to me, I'm wondering if anyone knows why its happening. The source seems to be 1.1.1.1 and destination is my phone. My router is a separate device and DHCP is also from the router, so I don't understand...
  17. S

    Syncing IP's from fail2ban

    I have been testing my script to copy fail2ban log files to Proxmox firewall and have managed to make it work... one time :) cat /root/bin/banned2proxmox.sh #!/bin/bash # # Sync fail2ban log files from client servers rsync -a root@vm1.ic4.eu:/var/log/fail2ban.log /root/bin/fail2ban-vm1.log...
  18. M

    Firewall: Inside or Outside

    Good Morning, currently i'm messing around with my local networks. I decided to add a DHCP Server and an option to reverse proxy some parts of my local net (green, blue) to campus (red) access. I have followed some youtube tutorials (german). Unfortunately, i can't get access to the pfsense...
  19. M

    Possible bug when renaming a security group

    Hello When I rename a firewall security group (on the cluster/dc level), it won't get renamed on the VM level and thus the security group no longer applies to that VM. Is that a bug or intended behaviour? Thanks.
  20. S

    Firewall-Problem

    Hallo, Ich scheine ein Firewall-Problem zu haben. Ich habe die Anwendung Passbolt (https://www.passbolt.com/) in einer VM laufen. Diese hat zwei IPs, eine IPv4 und eine IPv6. Freigegeben habe ich die beiden Web-Ports 80 und 443 mit dem Web-Makro. Zusätzlich gibt es noch eine Security-Group mit...