[SOLVED] Configure Firewall to seperate an subnet (DMZ)

fireon

Distinguished Member
Oct 25, 2010
4,478
466
153
Austria/Graz
deepdoc.at
Hello,

Situation:
- 2 real subnet (no VLANs)
- 2 Interfaces on Proxmoxhost
- 1 Interface for the DMZ (bind directly to fortigate)

So i would like to configure the firewall that VMs in the DMZ are not able to communicate over the physical Interface to the hostmachine. So i read the wikithread for firewallconfig. Is it really right that i must configure the firewall first for the host on all needed ports? I only need rules for this DMZzone. But sorry i not really know about this rules. It is not logical for me, ... some rules are not possible.

So for example. I would like to set a firewallrule vor VM100 that this vm can't connect to hostmachine on port 22. So what must i do?

Thanks for help
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!