Dear,
the documentation for the firewall is not the hit!
So I have make many tests and I cant understand, why not working correct!
First the host is a dedicated server in OVH. This working via IP throu MAC to the eth0 linked to vmbr0!
We are not working with clusters! So in the configuration of Proxmox-Datacenter is only this host!
a) I have enabled in Datacenter the firewall and in the host! Just in this moment I have done, the communication
between Proxmox GUI to the Firewall-Settings is inoperable! The Default-Setting with comming with the updates,
are setting in datacenter on Input-Policy DROP. When I change the firewallmode to 0 direct in the cluster.fs
then the GUI can handle the settings! Many other tests fails too!
b) I have add rule for an Ping from the Operating Center to the host. In this setting no ping is working, equal when
I use the interface eth0 or vmbr0, Protocol icmp and the IP ACCEPT.
b) Ok now I have set in the Datacenter the standard setting shull been Input-Policy ACCEPT and then I have create
a rule to block Ping from an other computer from outside to this host IP. The Rule is enable, but a ping is possible.
Thats equal as I set the interface to net0 or eth0 or vmbr0. All pings are going throu! I can set the rules in Datacenter
or in the Host, every time the same! And yes the firewall is enabled and iptables -L shows me the rulesettings and
pve-firewall status is working without errors!
c) I have test the same rule DROP ping from an IP from a container to the host and in the rule setting interface eth0 or
vmbr0. The ping is going throu and they dont drop the pings.
So in the docmentation is written interface net0 - Is this a logical interface, when clustering is used only?
Is that possible, that the firewall is not working correct, when its going via MAC?
Regards
Detlef
the documentation for the firewall is not the hit!
So I have make many tests and I cant understand, why not working correct!
First the host is a dedicated server in OVH. This working via IP throu MAC to the eth0 linked to vmbr0!
We are not working with clusters! So in the configuration of Proxmox-Datacenter is only this host!
a) I have enabled in Datacenter the firewall and in the host! Just in this moment I have done, the communication
between Proxmox GUI to the Firewall-Settings is inoperable! The Default-Setting with comming with the updates,
are setting in datacenter on Input-Policy DROP. When I change the firewallmode to 0 direct in the cluster.fs
then the GUI can handle the settings! Many other tests fails too!
b) I have add rule for an Ping from the Operating Center to the host. In this setting no ping is working, equal when
I use the interface eth0 or vmbr0, Protocol icmp and the IP ACCEPT.
b) Ok now I have set in the Datacenter the standard setting shull been Input-Policy ACCEPT and then I have create
a rule to block Ping from an other computer from outside to this host IP. The Rule is enable, but a ping is possible.
Thats equal as I set the interface to net0 or eth0 or vmbr0. All pings are going throu! I can set the rules in Datacenter
or in the Host, every time the same! And yes the firewall is enabled and iptables -L shows me the rulesettings and
pve-firewall status is working without errors!
c) I have test the same rule DROP ping from an IP from a container to the host and in the rule setting interface eth0 or
vmbr0. The ping is going throu and they dont drop the pings.
So in the docmentation is written interface net0 - Is this a logical interface, when clustering is used only?
Is that possible, that the firewall is not working correct, when its going via MAC?
Regards
Detlef