Hello,
I've got a Proxmox server that I need to connect to the internet directly (it is a hosted dedicated server).
I then have a single IPv4 and IPv6 addresses provided by the hosting provider which will be assigned to this server. An additional IPv4 subnet and additional IPv6 subnets will be then routed through to this host to allow me to assign to the VMs.
I will run pfSense to manage this, however I am currently trying to figure out how to use the builtin firewall inside Proxmox to secure the management interface (i.e. the single iPv4 and IPv6 addresses) so that only trusted hosts may access the proxmox web UI.
Before I set this up in production I am testing this out in a lab, but I am not having any luck with this. I've made the host firewall config changes but I am not getting the desired results (still have access from everywhere)
My host's IP is 10.12.18.230 and the management station IP is 10.12.18.61. So I set up an alias with 10.12.18.61 as "MGTipaddress", I then changed the datacenter default policy to drop. Then I created a firewall rule "type:" in and "source:" MGTipaddress.
I expected this to lock down the access so I can only access 10.12.18.230 from 10.12.18.61. However, I am able to access it from any IP on this subnet.
Have a look at the screenshots - have I missed something?
I've got a Proxmox server that I need to connect to the internet directly (it is a hosted dedicated server).
I then have a single IPv4 and IPv6 addresses provided by the hosting provider which will be assigned to this server. An additional IPv4 subnet and additional IPv6 subnets will be then routed through to this host to allow me to assign to the VMs.
I will run pfSense to manage this, however I am currently trying to figure out how to use the builtin firewall inside Proxmox to secure the management interface (i.e. the single iPv4 and IPv6 addresses) so that only trusted hosts may access the proxmox web UI.
Before I set this up in production I am testing this out in a lab, but I am not having any luck with this. I've made the host firewall config changes but I am not getting the desired results (still have access from everywhere)
My host's IP is 10.12.18.230 and the management station IP is 10.12.18.61. So I set up an alias with 10.12.18.61 as "MGTipaddress", I then changed the datacenter default policy to drop. Then I created a firewall rule "type:" in and "source:" MGTipaddress.
I expected this to lock down the access so I can only access 10.12.18.230 from 10.12.18.61. However, I am able to access it from any IP on this subnet.
Have a look at the screenshots - have I missed something?