help firewall configuration

daruom13

Member
Aug 1, 2020
31
2
13
38
Hello,

I would like to secure my Proxmox servers with the fireall.
However, I have a few questions:

For my VMs, I use Pfsense with a failover IP in front of the other machines. Is it necessary to put a rule to authorize the IP failover?

I don't fully understand how IP failover works.
I know it's bind to a MAC address add on the VM interface. But I don't know how this is "routed" to the VM. I do not see it in the Proxmox routes.

To be clearer, here is an example:
IP_PROXMOX = XX.XX.XX.XX
IP_FAILOVER = YY.YY.YY.YY
MY_HOME_IP = ZZ.ZZ.ZZ.ZZ

I want only MY_HOME_IP to be allowed to connect to IP_PROXMOX.
For IP_FAILOVER, no restriction (PfSense will take care of this).

If I understood correctly, there are different zones for the firewall?
One at the cluster level that applies to all hosts, and one at the host level that only applies to the server?

My cluster is in production, is it possible to "test" the rules or to go back (by restarting the server for example)?

Thank you in advance
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!