security

  1. H

    Security notice from my Netgear Armor scan

    Hey all! Perhaps a bit of a beginner question here, especially on the security side. I got a notice for 2 vulnerabilities with open ssh version that is running on ProxMox. It is mentioning that OpenSSH_8.4p1 is vulnerable on CVE-2023-28531 and CVE-2008-3844. Interestingly I think both of...
  2. F

    First Steps setting-up Proxmox

    Hello guys, Last weekend I managed to install and setup my first home server with Proxmox. I have used an a old desktop PC, boosted a bit the memory and succsefully installed Proxmox VE. Everything seems to be working just fine and I am enjoying my setup. However, I may need help for few...
  3. G

    LXC, trust of default templates

    A friend starting into using Proxmox asked me a question today which I didn't offhand know the answer to and couldn't find a definitive answer on here. How do you know the LXC templates are trustworthy? LXC containers (as in the templates pulled down from pveam), I'm guessing they're pulled...
  4. V

    Achieving Isolation for Sec (vm->vm & vm->Hyper)

    Building proxmox box which will host 20+ VMs. Need to ensure that: 1. VMs cannot talk to hypervisor, but VMs can all reach the internet 2. VMs cannot talk to other VMs 3. VMs cannot read or write to other VMs 4. Need to ensure that VMs cannot read or write to hypervisor Purpose is to avoid...
  5. L

    Falco / proxmox / lxc

    Has anyone experimented with Falco driver in Proxmox / Linux kernel and using it to secure containers? Use Case: Running Falco on a Linux host or running Falco userspace program in a container, with a driver installed on the underlying host. https://falco.org/docs/getting-started/
  6. M

    IPTables rules per guest VM

    Hi, After checking quite a few articles found here and on some other websites, it's still not clear for me how one can add custom IPTables rules for each VM. Checking the current host with just one VM at the moment I can see: -A tap100i0-IN -p udp -m udp --sport 67 --dport 68 -j ACCEPT -A...
  7. Z

    Proxmox Private Vlan Feature

    I'm migrating from VMWare-ESX to Proxmox. Previously I managed to used Private vlan on vmware and enhanced security for my customers and also used /32 IP address per customer. now I am not able to find a solution for this case in Proxmox. cloud anyone guide, what they have done to increase L2...
  8. P

    NIC PCI-Passthrough

    Abend zusammen, Wie „sicher“ ist eigentlich PCI-Passthrough? Ich bin aktuell am überlegen folgende Konstellation zu bauen: 1 Host mit einer zusätzlichen Netzwerkkarte. Die Karte hat 2x 10G. Die beiden Ports sollen per PCI-Passthrough an eine Virtuelle OPNsense weiter gereicht werden. Hinter...
  9. K

    [SOLVED] Questions regarding encryption

    Hi, i got 2 questions to properly secure my data. The setup is one server running PVE an another server running PBS. All on premise. The VMs are stored on thin-provisioned LVMs that are encrypted using LUKS. The key is stored on a hardware token. I am really happy with that. Works great and...
  10. A

    Suspicious frequent logs

    Apr 03 10:19:59 pve sshd[12301]: Unable to negotiate with 61.**.1*2.174 port 60790: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1 [preauth] Apr 03 09:56:19 pve sshd[9035]: Unable to negotiate with...
  11. C

    A lot more Kernel Vulnerabilities (Spectre V2, DoS of Hypervisor from KVMs, etc.)

    Hi, seems like Dirty Pipe wasn't the only vulnerability keeping us busy this week. I got notified about these new Security Advisories from Debian: https://www.debian.org/security/2022/dsa-5095 https://www.debian.org/security/2022/dsa-5096 I know Proxmox uses a modified Ubuntu Kernel but I was...
  12. P

    DirtyPipe (CVE-2022-0847) fix for Proxmox VE

    Dear Proxmox Team as of today a new security issue was published which also affects the kernels available for proxmox 7. it is dubbed dirtypipe and seems to allow privilege escalations on affected systems. all details can be found here: https://dirtypipe.cm4all.com/ i checked on my proxmox...
  13. H

    can core_pattern be modified from privileged CT?

    i've just found this: https://pwning.systems/posts/escaping-containers-for-fun/ They simply set /proc/sys/kernel/core_pattern to execute user provided binary in host context by triggering coredump inside of privileged docker container. Can this be done with privileged CTs on proxmox? Or is...
  14. P

    Webinterface Zugriff absichern

    Guten Abend zusammen, ich bin aktuell dabei mein neuen Proxmox Host einzurichten. Der Host steht bei einem Anbieter im Rechenzentrum. Ich habe leider aktuell keine Möglichkeit den Host hinter eine Firewall etc. zu hängen, und versuche den Zugriff auf den Host so gut wie möglich abzusichern...
  15. W

    Proxmox Secure Communications Configuration

    This may end up being quite a loaded question but… What would be the best/easiest way to setup SSL/secure communication for the WHOLE server including all VMs and Containers? Is it possible to have local/LAN access ONLY, with remote access only available via a VPN/tunnel? Would it be possible...
  16. B

    Spectre / meltdown / ... mitigations: Host OS, VM-CPU, VM-OS, ...

    Hi, I have a question regarding required mitigation measures against spectre / meltdown / ... on different levels, i.e. what is needed where. As I understand it, already the host OS - Debian contains mitigations according to lscpu output: Vulnerability Itlb multihit: Not affected...
  17. D

    [SOLVED] Sicherheitslücke im Kernel CVE-2021-33909

    Hallo zusammen, nach der Meldung einer Sicherheitslücke im Linux-Kernel haben wir bei uns alle Server gepatcht, jetzt ist allerdings unklar ab welcher Version der PVE Kernel nicht mehr verwundbar ist. Habt ihr dazu die Infos? Über Google konnte ich leider nichts finden... Unsere PMGs stehen...
  18. F

    Absicherung Proxmox

    Hallo zusammen, ich bin neu in der Welt Proxmox und somit auch neu hier im Forum. Ich bin zurzeit im 3 Lehrjahr in meiner Ausbildung zum Systemintegrator, und habe mir seit gut einem halben Jahr ein Server bei einem Hoster gemietet. Auf dem Server experimentiere ich einfach ein wenig rum...
  19. B

    [SOLVED] Viewing Failed Login attempts

    Hi everyone. Can someone point me in the direction of a log that records logins to the PMG interface (Failed and successful). Hoping it also records the IP address of the login attempts. Thanks!!
  20. L

    Security Onion

    Hello, is it possible to mirror the network traffic of 1 virtual port in proxmox without tc? vmbr0 --> 6 virtual ports (important ens33, ens18) i want to mirror ens33 to ens18 that the Security Onion can only see her traffic is that possible without tc because tc not working for me Greets

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!