The Firewall Wiki page https://pve.proxmox.com/wiki/Firewall explains
I think quite a lot of Proxmox users have the server in a remote located datacenter, so local network isn't an option. I'd like if someone could give a more clear explanation of how to just block the access to port 8006 without affecting the traffic anywhere else.
I can of course just setup a couple of iptables lines to accomplish the objective, but it seems pointless to have a firewall interface and then not using it.
The Wiki page also claim that "The cluster wide firewall configuration is stored at: /etc/pve/firewall/cluster.fw". It isn't on my server - no firewall directory exist under /etc/pve. Could be it just needs to be created, but it could also be that the documentation is outdated, and I lock myself out if I start messing with it.
It would be nice with an example explaining how to setup a basic access control to only allow access to GUI and perhaps SSH from given IP addresses.
It would also be nice to know where login activity for the GUI is logged. Nothing is logged under /var/log, perhaps somewhere else? Surely Proxmox must be logging login activitiy on the GUI?
If you enable the firewall, traffic to all hosts is blocked by default. Only exceptions is WebGUI(8006) and ssh(22) from your local network. |
I think quite a lot of Proxmox users have the server in a remote located datacenter, so local network isn't an option. I'd like if someone could give a more clear explanation of how to just block the access to port 8006 without affecting the traffic anywhere else.
I can of course just setup a couple of iptables lines to accomplish the objective, but it seems pointless to have a firewall interface and then not using it.
The Wiki page also claim that "The cluster wide firewall configuration is stored at: /etc/pve/firewall/cluster.fw". It isn't on my server - no firewall directory exist under /etc/pve. Could be it just needs to be created, but it could also be that the documentation is outdated, and I lock myself out if I start messing with it.
It would be nice with an example explaining how to setup a basic access control to only allow access to GUI and perhaps SSH from given IP addresses.
It would also be nice to know where login activity for the GUI is logged. Nothing is logged under /var/log, perhaps somewhere else? Surely Proxmox must be logging login activitiy on the GUI?