[SOLVED] Dose PVE support guest access to trunk topology?

Aug 3, 2019
9
0
21
31
Hello, And:

I got: A PVE Cluster, A Managed Switch, And an access port from Core Switch ( That's the point, vlan and turnk will only exist in my private zone).

I want:
- Access PVE WebUI in vlan A
- Put trusted infrastructure like ntp dns in vlan B
- Put shared but trusted software (for dev) like jenkins gitlab in vlan C
- Put untrusted software (wrote by dev) dev/fat/uar/pre in vlan D
- Put untrusted VMs (used by devs playground) in vlan E

The meaning of Vlan is block boardcast, So I can devide trust and untrust zone.

So here is the problem:

If there is no requirement vlanE, I can simply use any config in `https://pve.proxmox.com/wiki/Network_Configuration`. But, Developers will grant root access of guest VM, SO I can't depend on any `configuration in the guest necessary.` solution. If they can do it, It will be an invasion.

Is this config mean : Give guest an access port and tag the traffic as 8021Q to vmbr0? So the trunk is transparent for guest?

1.jpg
 
Hi,

if I understand you correctly, you basically just want the traffic generated by a VM to be tagged by the host (i.e. not by the VM itself)? If so you have two options:

  • Set the vlan tag on each VM by configuring the NIC (e.g. under VM > Hardware, then select the NIC, hit "Edit" and set the "VLAN Tag", so basically what your screenshot shows).
  • Setup a new VLAN under "Node name" > Network with the desired tag. Then setup a bridge on top of that VLAN. You can then base all the NICs you want on that bridge an they should also get tagged with the desired tag.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!