Micro segmentation/port isolation - what is the best way to go about this

Jul 7, 2021
29
2
1
Hi,
We're experimenting with proxmox and I'm hoping I'll be able to bring it in to replace VMware.

One of the things I very much would like to do for "DMZ" servers is have microsegmentation/port-isolation (ie the only way for them to talk to other servers is through the firewall).

I could of course create a lot of vlans but that is not really scalable in the long run (since the number of vlans is limited to 4000, though I don't expect to have that many vms having a vlan per vm would still mean a ridiculous amount of management overhead).

So what is the best solution for such a thing? OpenVswitch? some other cool proxmox feature I don't know yet?
Thanks!
 
Hi,
We're experimenting with proxmox and I'm hoping I'll be able to bring it in to replace VMware.

One of the things I very much would like to do for "DMZ" servers is have microsegmentation/port-isolation (ie the only way for them to talk to other servers is through the firewall).

I could of course create a lot of vlans but that is not really scalable in the long run (since the number of vlans is limited to 4000, though I don't expect to have that many vms having a vlan per vm would still mean a ridiculous amount of management overhead).

So what is the best solution for such a thing? OpenVswitch? some other cool proxmox feature I don't know yet?
Thanks!
proxmox firewall
 
proxmox firewall
Using your firewall for micro-segmentation, turns your firewall into a bottleneck. The more you scale up your network, the bigger problem this becomes. At least, I'm pretty sure this is the case.

The other problem is management. Managing firewall rules with many small subnets quickly becomes a massive headache. Or so they say.
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!