Private VLAN/ micro segmentation in Proxmox

Pandry

Active Member
Jun 30, 2016
5
0
41
I know it has been asked multiple times (I’ve found result both in english and in german), but I was wondering if the bridge port isolation on Linux was something being considered for the roadmap, since it is already available on linux:
2D409633-A75D-444D-9699-36D46F99E2E6.jpeg

I am interested in policing the intra-boadcast domain traffic in a network.

I already know there is the SDN feature (that I’m going to try soon!) and the Proxmox firewall capability, but I’m scared that L2 traffic may pass anyway (and it is yet another place to write policies in): having the bridge port isolation at Layer 2 may allow me to use a central firewall for managing the rules.

Writing some of the rules on the main firewall and some in the Proxmox firewall would be error prone and time consuming (if I’m not doing it wrong, anyway).

Now, I understand my question is probably wrong and I totally agree that a distributed firewall at the hypervisor level is both more scalable and performant, but I feel I’m unable to use the Proxmox firewall as I should/want

Also, is there a date for when the SDN feature will be formally released as stable?
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!