Network / Firewall issue ?????????

Netizen

Member
Aug 16, 2012
88
0
6
Network / Firewall issue


So far I had KVMs and CTs with public IPs assigned to them however this is now not possible due to the limit of amount of IPs I can have per server from the DC I am in.

I have therefore decided to start having KVMs with private IPs using NAT redirects of the main server IP to the various internal KVM guest.
When however I decided to put a firewall on those KVMs (software fw) I realised that I cannot have rules matching specific remote hosts because all the traffic is visible as coming from the hardware node main IP and not the remote IP.
I therefore cannot create rules with remote IPs to block or to allow as I only see my main IP.

What is the method to overcome/solve this? (Expect hardware firewall please, this is not an option).

:(
 
Last edited:
Well, I think it's normal because you are doing nat ....

Do you have tried in routed mode or bridge mode ?

Wrong answer.
Think of the NAT you operate (usually) on a home router. You PCs on the LAN still see the remote (foreign) IPs as sending traffic. Not the gateway itself (the home router).
 
If you're doing dnat on specific ports or port ranges to help fully utilise your available public subnet, then the remote host address doesn't change. I'm curious about the rules too. On a side note, if you want your specific virtual hosts to be seen from different public ip addresses, you should use snat to achieve that (outbound connections). I'm doing the same on several hosts because it makes networking a lot more flexible and easier to secure (that is, even if I have enough public IPs, I still use NAT).
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!