[SOLVED] Can't get firewall to block traffic

nck

New Member
Aug 25, 2015
3
0
1
Hey,

I am running Proxmox VE 3.4-6 with some hosts as Virtual Machine. On my top-most node I "enabled" the firewall and added a security group, that's "enabled" to. For testing purposes I added a rule to reject all incoming SSH-traffic. (Direction: In, Macro: SSH, Action: Reject, Enabled: Ticked).

On my first node I enabled the firewall, too. On my testing host I enabled the firewall, too, and under "rules" I added the security group specified above and "enabled" it, too. I left "interface" blank. I also enabled logging_in and logging_out and set it to "info"-level.

Now I am checking the port from outside (using www*youtgetsignal*com/tools/open-ports). I entered my IP-address and port 22.

But it's still open and there are no logging events in the log.

What am I doing wrong?

Thanks in advance,

cheers!
 
Last edited:
yes, I enabled it three times - on Datacenter level, one level beyond, my vm-container and last but not least on the host.
 
Thank you so much. It wasn't enabled. Its working now!

(is that some kind of feature, 4 confirmations in a row? ^^)
 
Haha, no problem :D


First I though that also for a moment, but it makes sense though, you can configure it for every level and interface separately, which is nice to have. Also Datacenter level normally has to be enabled only once in a clusters lifetime and node level is default already enabled...^^
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!