Hi,
My objective is simple; I want to restrict traffic between guests on a cluster within the same subnet (VNet), while allowing explicit exceptions and upstreams traffic.
I see that an isolation option exists for VNets, with the following footnote:
I'm not real sure what that means. Are they only going to be isolated from one another if they run on the same host? I need to use VNet firewall in order to isolate guests on different hosts? Why isn't either enough?
Anyway, I tried enabling the isolate option on the VNet, applying the SDN configuration and restarting my two guests through PVE, but they can still ping each other. They are running on the same host. Do I also need to enable one or more of the plethora of other firewall options?
My objective is simple; I want to restrict traffic between guests on a cluster within the same subnet (VNet), while allowing explicit exceptions and upstreams traffic.
I see that an isolation option exists for VNets, with the following footnote:
Port isolation is local to each host. Use theVNET Firewall to further isolate traffic inthe VNET across nodes. For example, DROP by default and only allow traffic fromthe IP subnet to the gateway and vice versa.
I'm not real sure what that means. Are they only going to be isolated from one another if they run on the same host? I need to use VNet firewall in order to isolate guests on different hosts? Why isn't either enough?
Anyway, I tried enabling the isolate option on the VNet, applying the SDN configuration and restarting my two guests through PVE, but they can still ping each other. They are running on the same host. Do I also need to enable one or more of the plethora of other firewall options?
