misunderstanding Firewall

Sylvain2000

New Member
Mar 30, 2024
8
0
1
Hello, I'm discovering Proxmox and I think I might be misunderstanding the Proxmox firewall, at least the zones.

In my understanding, rules applied to the datacenter zone are replicated onto the nodes and the VMs within those nodes. For example, if we allow ping, then ping will be allowed on all nodes and all VMs (where the firewall is enabled).

The nodes zone replicates onto the Proxmox Virtual Environment (PVE) and the VMs within that PVE (where the firewall is enabled).

The VM zone only operates on the VMs.

is that correct or i wrong ?

Thank you for your help. I'm struggling.
 
ok so datacenter rules are replicated on all nodes but not vm's and rules on nodes are applied only for this nodes and not its vm's.
 
Thanks, and last question, yesterday I tested the firewall a bit. I set a rule on the data center to allow port 8006 and activated the firewall on the nodes and my VM. After that, I couldn't access the console of my VM anymore. Do I need to allow something to regain access? I thought the console was allowed by default in the anti-lockout rules.
 
I won't have access to my servers until Tuesday, but here are some screenshots I took. First screen is on the datacenter allow 5900:5999 and mangement . Second is on pve i was trying to allow spice.The third screenshot shows the error I encountered on my VM. It won't open Spice, and it tells me that it can't connect to the console. (It works when the data center firewall is turned off.)Capture d'écran 2024-03-29 144131.png


Capture d'écran 2024-03-29 160810.pngCapture d'écran 2024-03-29 144217.png and management
 
The order of my screenshots has changed, so it's the error first, then the data center(The smallest screenshot) , and finally the PVE.
 
be careful in flooding the forum.
users answers on their freetime.
if you need fast answers, buy support subscription.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!