Latest Proxmox 5.0-32 @OVH - Firewall

Xela

Well-Known Member
Oct 12, 2017
92
2
48
Hi there,

I have a dedicated server @OVH installed with the latest Proxmox VE 5 provided by OVH.

After the first steps of securing the server (sudo, ssh, etc.) I moved over to the Proxmox FE and implemented the very good explained recommendations from "kiloroot.com/secure-proxmox-install-sudo-firewall-with-ipv6-and-more-how-to-configure-from-start-to-finish/" regarding the Proxmox Firewall. My experience after the implementation was, that I had to install the server again because of IPv6 failures. I checked for the IPv6 loopback and "ifconfig lo" gave the result "inet6 ::1 prefixlen 128". IPv6 loopback is available.

I found another documentation "cedric.net/firewall-on-proxmox-ve4/" and they recommend to fix a) The rpd/statd configuration should be edited. b) On OVH’s Proxmox releases, the BIND configuration should be fixed so that it listens on localhost only.

Are there any recommendations how to solve that, that the Firewall is running also with IPv6 at OVH?
 
Meanwhile I discovered that BIND is listining on localhost. Implemented the Firewall rules again (kiloroot). 5 minutes later I am getting a connection error to the node. SSH says "Packet_write_wait: Connection to xxx.xxx.xxx.xxx port yy: Broken pipe". Still can connect via SSH to the HOST.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!