Hi,
Being a Proxmox newbie, this may be a no-brainer to the forum members, but anyhow.
I have activated the datacenter FW in its default settings in DROP, out ACCEPT.
Next I have activated the FW on one of the VMs, with its default settings in DROP, out ACCEPT. Setup inbound rules, e.g. 3000 ACCEPT, 2055 ACCEPT (yes this is ntopng). Works fine for local network and other home network (I had set aliases with CIDR notation on the datacenter level, and using those to define inbound rules).
However, all outbound traffic seems to be blocked, e.g. cannot ping another machine on the subnet, apt-get upgrade gets nowhere, and DNS get stuck as ntop is not resolving IP on the web console.
Switching off the VM FW does not help, only switching off the FW on datacenter level does, but that's to be expected as then there no FW functionality at all.
Being naive I thought out ACCEPT would allow any outbound connection from the VM, with also the data center having an out ACCEPT setting.
Obviously I am doing something wrong here? To be honest I have not touched the cluster FW, but that does not seems to have a default in DROP / out ACCEPT rule, or should I?
Thx. Regs, Mark
Being a Proxmox newbie, this may be a no-brainer to the forum members, but anyhow.
I have activated the datacenter FW in its default settings in DROP, out ACCEPT.
Next I have activated the FW on one of the VMs, with its default settings in DROP, out ACCEPT. Setup inbound rules, e.g. 3000 ACCEPT, 2055 ACCEPT (yes this is ntopng). Works fine for local network and other home network (I had set aliases with CIDR notation on the datacenter level, and using those to define inbound rules).
However, all outbound traffic seems to be blocked, e.g. cannot ping another machine on the subnet, apt-get upgrade gets nowhere, and DNS get stuck as ntop is not resolving IP on the web console.
Switching off the VM FW does not help, only switching off the FW on datacenter level does, but that's to be expected as then there no FW functionality at all.
Being naive I thought out ACCEPT would allow any outbound connection from the VM, with also the data center having an out ACCEPT setting.
Obviously I am doing something wrong here? To be honest I have not touched the cluster FW, but that does not seems to have a default in DROP / out ACCEPT rule, or should I?
Thx. Regs, Mark