Hello,
I'm running Proxmox 4.2 on an OVH server w/ the standard OVH setup. Inside a LXC container there's Webmin listening on ports 10000/tcp and up, Webmin folks say it should suffice to open ports unto 10010/tcp for RPC access.
I'm using the Proxmox firewall and have restricted access to such ports to a number of static source IPs. I've used an IP set for that purpose, containing two IPv4 and one IPv6 addresses.
Datacenter: FW is on, default IN policy is DROP. A rule allows access via vmbr0 to tcp ports 10000:10010 from our IP set.
Node: FW is on. A security group allows all traffic from our IP set.
Host: FW flag on net0 is ON. FW is on. Again, the same security group allows all traffic from our IP set.
Access to port 10000/tcp is available from allowed IPs and filtered for others.
When I try to connect to port 10001/tcp from a host using an allowed source IP, that host will tell me that this port is firewalled and unavailable. I've tried everything I could think of but can't seem to be able to open that port. What am I doing wrong? Regards
Christian Aust
I'm running Proxmox 4.2 on an OVH server w/ the standard OVH setup. Inside a LXC container there's Webmin listening on ports 10000/tcp and up, Webmin folks say it should suffice to open ports unto 10010/tcp for RPC access.
I'm using the Proxmox firewall and have restricted access to such ports to a number of static source IPs. I've used an IP set for that purpose, containing two IPv4 and one IPv6 addresses.
Datacenter: FW is on, default IN policy is DROP. A rule allows access via vmbr0 to tcp ports 10000:10010 from our IP set.
Node: FW is on. A security group allows all traffic from our IP set.
Host: FW flag on net0 is ON. FW is on. Again, the same security group allows all traffic from our IP set.
Access to port 10000/tcp is available from allowed IPs and filtered for others.
When I try to connect to port 10001/tcp from a host using an allowed source IP, that host will tell me that this port is firewalled and unavailable. I've tried everything I could think of but can't seem to be able to open that port. What am I doing wrong? Regards
Christian Aust