So far I've one PVE node with two NIC. One is LAN (enp7s0 / vmbr0) and one is DMZ (enp8s0 / vmbr1). I would like to prevent anything on the DMZ from accessing the PVE Web UI.
Can I do this using the Datacenter firewall UI? I tried the following from the Web but it didn't work when testing from a VM on the DMZ network.
Direction: In
Action: Drop
Interface: vmbr1
Source: 172.16.16.0/24
Destination: 172.16.16.55 (my PVE server)
Surprisingly, I found that it did work if I switched on the individual node firewall, but I assume that wouldn't scale well if/when I graduate to a cluster.
Thanks
Can I do this using the Datacenter firewall UI? I tried the following from the Web but it didn't work when testing from a VM on the DMZ network.
Direction: In
Action: Drop
Interface: vmbr1
Source: 172.16.16.0/24
Destination: 172.16.16.55 (my PVE server)
Surprisingly, I found that it did work if I switched on the individual node firewall, but I assume that wouldn't scale well if/when I graduate to a cluster.
Thanks