Firewall rule to only allow specific IP's to one VM

vs2015sv

New Member
Aug 3, 2022
2
0
1
Hello,

I am running a demo nethserver (domain) VM in proxmox 7.1-12 along with many other VM's.

I would like to restrict which IP's can access the nethserver cockpit (Http://IP address&port) (Just one VM) via the proxmox firewall.

Could I please get some advice on how to properly do this?
From the videos I watched, they say you need to enable ssh and http access in the firewall or you will be locked out?


Again, I want to keep everything how it is but just limit which IP's can log into the cockpit.

Thanks!
 
Last edited:
you simply need to add firewall on this specifc vm.

configure default incoming rules to rejet or deny, then add accept rules for each ips. (or better, create an ipset with all ips, and add 1 accept rule for this ipset )
 
So I just need to enable the firewall at the datacenter level and then go into the VM and add specific firewall rules?
I won't get locked out if I don't add a ssh rule to the datacenter?
 
So I just need to enable the firewall at the datacenter level and then go into the VM and add specific firewall rules?
I won't get locked out if I don't add a ssh rule to the datacenter?
you can enable firewall at datacenter level && disable it on hosts. (I'll still works on vm)
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!