Hi.
I have about 10 KVM virtual machines on my production Proxmox environment, and now I want to think about some firewall policies, and I want to discuss with you about that.
One way could be to install Shorewall on my Proxmox installation, or to install a pfSense virtual machine wich uses a bridged interface for the WAN and another bridged interface for the LAN, and have my virtual machines all on that brided interface on the pfSense's LAN network. But I'd need to use 1:1 NAT and I don't want this, because I want the IP addresses to be assigned on the virtual machine.
Another way could be using a separate bridged interface for each virtual machine and use Shorewall on Proxmox or pfSense on another virtual machine to make some packet filtering rules and some accounting.
Do you have any suggestion?
Thank you very much for your help!
Bye.
I have about 10 KVM virtual machines on my production Proxmox environment, and now I want to think about some firewall policies, and I want to discuss with you about that.
One way could be to install Shorewall on my Proxmox installation, or to install a pfSense virtual machine wich uses a bridged interface for the WAN and another bridged interface for the LAN, and have my virtual machines all on that brided interface on the pfSense's LAN network. But I'd need to use 1:1 NAT and I don't want this, because I want the IP addresses to be assigned on the virtual machine.
Another way could be using a separate bridged interface for each virtual machine and use Shorewall on Proxmox or pfSense on another virtual machine to make some packet filtering rules and some accounting.
Do you have any suggestion?
Thank you very much for your help!
Bye.