How block in ports in proxmox firewall

powersupport

Active Member
Jan 18, 2020
248
2
38
29
Hi,

I am trying to block a port for a VM on proxmox for incoming traffic, but it looks not working, please refer to the rule I created in the attachment.
Anyone can advise on this?

Also, actually, I am looking to block all the ports for incoming traffic except a few(for VM), is it possible? if so, anyone can share the steps here

Thank you
 

Attachments

  • firewall.png
    firewall.png
    20.1 KB · Views: 100
  • firewall2.png
    firewall2.png
    18.5 KB · Views: 99
Did you enable the firewall on datacenter level? If not no VM/host firewall rules will be active.
 
Yes, the Firewall in the data center is enabled, it is in the screenshot I shared.

Thank you
 
Also, actually, I am looking to block all the ports for incoming traffic except a few(for VM), is it possible? if so, anyone can share the steps here
Where do you create those rules? Node firewall rules will only count for the host itself and not for guests. Guest firewall rules will only count for the VM/LXC it was created for but not for the host. Datacenter firewall rules will effect all nodes of a cluster (but not guests).

The datacenters/nodes/guests firewall default incoming policy should be set to drop by default, so every incoming port of your host/guest should be closed by default (except for the hidden anti lockout rules for your host). So easiest would be to keep it that way and just whitelist ports the guest actually needs by creating allow rules for each port the guest needsto be accessed from.
 
Last edited:
Hi,
>Where do you create those rules
Please have a look at the screenshot attached above.

We are looking to block all the ports for incoming traffic for a VM. We have enabled it in the Datacenter.
No need to block traffic for the Proxmox host, we are only looking to enable firewall rules for virtual machines

Regards,
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!