As noted in another thread (can't post links yet: forum.proxmox.com/threads/22923-pve-Firewall-Default-policy-on-node-and-VM-level-And-how-to-make-it-works-with-CT?p=117671#post117671), I concur that the default firewall rule set in Datacenter->Firewall->Options as Input policy->DROP does not work as expected. I expect this to drop any incoming connections except those I explicitly set in the Rules directly via included Security Groups. However, when I disable the Security Group rule I have for ssh, I can still connect with ssh. So I've added a general catch-all DROP rule and dragged it to be the last rule in my list because the order of precedence in the Proxmox Firewall Rules GUI.
Has anyone else found the default Input Policy doesn't work as expected?
Has anyone else found the default Input Policy doesn't work as expected?
Last edited: