Private VLAN setup

potatowithalaser

New Member
Apr 3, 2024
1
0
1
Hello,

On my Proxmox server, I have PfSense as a VM. A NIC is directly passed through as a PCIE device to PfSense, and is entirely invisible to Proxmox, which serves as "WAN". enp9s0 is the "LAN", and vmbr0 is using enp9s0 as the bridge port. vmbr0 is configured with ipv4 10.0.0.2/24, and gateway as 10.0.0.1, and is VLAN aware. Currently, it serves both Proxmox itself, and all connected VM's/Containers.

1712178292584.png

Let's take 2 VM's for example: VM 1 with VLAN tag 20, and VM 2, also with VLAN tag 20. In PfSense, I have networking rules to disable communication within the VLAN. However, Proxmox is currently routing VM 1 to VM 2 internally without going through the PfSense firewall, and allowing traffic. What is the best way to disable Proxmox from routing 2 devices within the same VLAN?

Thank you in advance for the help!
-Potato
 
In PfSense, I have networking rules to disable communication within the VLAN.
How? IPs within a subnet are always able to directly communicate with eachother without anything needing to be routed so pfsense won't do any firewalling unless connections would need to leave that subnet.
Proxmox is currently routing VM 1 to VM 2 internally without going through the PfSense firewall, and allowing traffic.
For that you usually make use of the PVE firewall and set up firewall rules for each VM.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!