Firewall issues

Dimitar Yanakiev

New Member
Jun 30, 2018
10
0
1
26
Hello,
I have few issues with the proxmox firewall, i use latest proxmox 5.2-1.
I have enabled datacenter firewall
Input policy is DROP
Then i have three other rules to allow ssh,8006 and reject ping.
The problem is that yougetsignal.com/tools/open-ports says that all the ports are open when they are not, how can i solve this issue?

Another thing is that after i change firewall for a container i need to reboot the container in order the rule to apply is this normal?

I attached proxmox report.

Thanks.
 

Attachments

  • srv17781-report-Sat-30-June-2018-13-19.txt
    64.1 KB · Views: 6
This appears to be a similar issue to mine (although I'm using an older version of PVE).

When you say "yougetsignal.com/tools/open-ports says that all the ports are open" do you mean open on the guest(s) or the host itself? I note that with me, ports are coming up (correctly) as "filtered" when I scan the host, but not the guests. So something is working, but not at the guest level.

One thing that's slightly odd is the node level. The docs say host related configuration is read from: /etc/pve/nodes/<nodename>/host.fw. But I don't have that file on my system. Do you?

Also, possibly in relation to your question about rebooting containers, the docs say:

The firewall requires a special network device setup, so you need to restart the VM/container after enabling the firewall on a network interface.

But that appears to be only when you first enable the firewall on a network device. I wonder what it means by "a special network device setup" though?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!