firewall rules not working

tl5k5

Well-Known Member
Jul 28, 2017
56
1
48
51
Hey all,
I'm setting up a lab with a Proxmox/ceph 3 node cluster.
WAN is being provided by a pfsense VM on a different PVE (running multiple pfsense instances for different uses) where the rules are set to block all traffic in the lab LAN except for a specific range of management IP addresses that can access the web.
For some reason, the range of blocked IP's can still ping any system that's a part of the PVE cluster.
Any of these "blocked" VM IP address, along with each cluster node, is completely accessible.
This same blocked range can not do anything else...they can't ping each other, they can't get to the web, etc.

Any reason why it does this? My best guess is the OVS Bridge requires firewall rules on the PVE node?

Thanks!
 

Attachments

  • Selection_003.png
    Selection_003.png
    33.9 KB · Views: 14
You can only block traffic to other subnets on the pfsense. Lan traffic does not route over the gateway (pfsense).

You can however use the pve firewall to limit it.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!