Private VLAN

intern0t

New Member
Dec 7, 2021
1
0
1
37
Hi,
Is it possible to enable PVLAN / VM ISOLATION on Proxmox?

Due to security requirements, we want to inspect traffic between VM's in the same subnet.

If we remove the local route on the host, all traffic to VM's on the same subnet will go via the firewall (external hardware outside of ProxMox).
However, if the host were to be compromised, an intruder could easily add the route and it will bypass the firewall again. This would not be a problem if we applied firewall rules in ProxMox, but this will currently not work, as the packet will still include source/destination even if it goes via the firewall, hence blocking all traffic.

Does it exist a proper solution to deploy this for production use?

Thank you.
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!