[SOLVED] Firewall configuration for Softether VPN in Windows VM

davidki

New Member
Apr 4, 2024
2
0
1
Hello to everyone
I have setup a Windows Server 2022 in a virtual machine and installed Softether VPN on that machine. Clients can connect from outside the LAN and have access to resources inside the LAN as well as to the internet. All good to this point.

But as soon as I enable the Proxmox host firewall for the VM, clients lose connection to the LAN but can still connect to the Softether VPN-Server, get an IP from my DHCP-Server and show up in Softether VPN Manager as connected.

In the Proxmox Host Firewall Port 992 used by Softether VPN is set to accept connections on TCP and UDP. The output policy of the firewall is set to accept, input policy is set to drop. At the end of the firewall I have a drop everything rule.

Because everything works without the firewall, I guess I missed something in the configuration of the host firewall.

Does anybody have an Idea what can be the cause of this issue? Or an idea where to look?
 
As, seems you use SoftEther as bridge, you need to set MAC Filter to No in VM Firewall Options.
 
@_gabriel Thank you for comment! That was the solution to my problem.
If anybody else is wondering, what the setting is doing: the MAC Filter prevents that the Guest is using different MACs then those specified in the hardware settings. This is to avoid MAC spoofing.
But in case of Softehter with LAN-Bridge the clients communicate with a different MAC through the VPN-Server (the Guest). Therefore this setting should be set to no.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!