Hey everyone!
I have read the PVE Firewall documentation plus a bunch of posts on these forums and, if I have understood correctly, there is no way to configure a single rule allowing ping among all LXC in the nodes of a Proxmox 7 cluster as rules at the datacentre level don't apply to containers, and neither do rules at the node level. So the only solution is to create the rule in each an every LXC firewall:
And if I wanted to apply a number of rules to all containers, then I could create a security group, add the rules there, and apply the security group to each and every container.
But there is no way to create a rule once and tell Proxmox to apply it to a given list of containers (all of them or a subset). I've seen some people call this feature "inheritance" on these forums. Correct?
If so, is there any feature request I could upvote?
I have read the PVE Firewall documentation plus a bunch of posts on these forums and, if I have understood correctly, there is no way to configure a single rule allowing ping among all LXC in the nodes of a Proxmox 7 cluster as rules at the datacentre level don't apply to containers, and neither do rules at the node level. So the only solution is to create the rule in each an every LXC firewall:
Type | Action | Macro | Interface | Protocol | Source | S. Port | Destination | D. Port | Comment |
in | ACCEPT | Ping | net0 | ipv4_private_guests | ipv4_private_guests | Allow ping from any LXC |
ipv4_private_guests
is an alias for the private network 192.168.0.0/24
.And if I wanted to apply a number of rules to all containers, then I could create a security group, add the rules there, and apply the security group to each and every container.
But there is no way to create a rule once and tell Proxmox to apply it to a given list of containers (all of them or a subset). I've seen some people call this feature "inheritance" on these forums. Correct?
If so, is there any feature request I could upvote?