[SOLVED] Host unreachable with firewall

Discussion in 'Proxmox VE: Networking and Firewall' started by Laurent Minne, Nov 29, 2018.

  1. Laurent Minne

    Laurent Minne New Member
    Proxmox VE Subscriber

    Joined:
    Jun 11, 2018
    Messages:
    9
    Likes Received:
    0
    Hello all,
    I am currently configuring my firewall and I have an issue when I activate it I can't reach my host...

    So, my case :

    I have add two rules in "Datacenter" to open 22/tcp & 8006/tcp, the source is set at 0.0.0.0 and the destination is set up at 149.202.X.X.

    Content of /etc/pve/firewall/cluster.fw
    Code:
    [RULES]
    IN ACCEPT -i vmbr0 -source 0.0.0.0 -dest 149.202.X.X -p tcp -dport 8006 -sport 8006 # Proxmox WebGUI
    IN SSH(ACCEPT) -i vmbr0 -source 0.0.0.0 -dest 149.202.X.X # SSH Access
    
    When I switch to enable the firewall on the "Datacenter" my proxmox become unreachable after few seconds...

    I don't understand where is my misstake.

    Someone have idea to help me ?

    In advance thank you for your interest.
     
  2. dcsapak

    dcsapak Proxmox Staff Member
    Staff Member

    Joined:
    Feb 1, 2016
    Messages:
    2,924
    Likes Received:
    266
    this looks wrong, since the source port is (often) randomized by the client
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
    Laurent Minne likes this.
  3. Laurent Minne

    Laurent Minne New Member
    Proxmox VE Subscriber

    Joined:
    Jun 11, 2018
    Messages:
    9
    Likes Received:
    0
    Thanks for your return I do the modification immediately.

    For SSH have you an idea ?
     
  4. dlimbeck

    dlimbeck Proxmox Staff Member
    Staff Member

    Joined:
    Aug 1, 2018
    Messages:
    65
    Likes Received:
    2
    If you remove the source address it should be any (0.0.0.0/0). If you specify one it is assumed to be /32.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
    Laurent Minne likes this.
  5. Laurent Minne

    Laurent Minne New Member
    Proxmox VE Subscriber

    Joined:
    Jun 11, 2018
    Messages:
    9
    Likes Received:
    0
    Many thanks for your answer !

    I'll test that soon as possible and I'll give a feedback ;-)
     
  6. Laurent Minne

    Laurent Minne New Member
    Proxmox VE Subscriber

    Joined:
    Jun 11, 2018
    Messages:
    9
    Likes Received:
    0
    It is solved.

    Thanks for your help !
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice