Hi all,
i'm facing some really basic issues related to firewall i think... i'm in the middle of trying to build up a firewall, but before even going any deeper i need to get basic things working and tested.
So here a basic example of things i can't the firewall to work with....
- DATACENTER, firewall enabled
Default input policy: DROP
Default output policy: ACCEPT
Rules:
1. allow traffic on vmbr0, port 8006 - looks to be working.
See picture if needed: https://imgur.com/a/BFABgbq
- NODE - firewall enabled
Rules:
1. no rules added here
See picture if needed: https://imgur.com/a/lqDF67u
- VM- firewall enabled
Default input policy: DROP
Default output policy: ACCEPT
rules:
1. added "in" "drop" "icmp" - https://imgur.com/a/fuBxwxb
See picture if needed: https://imgur.com/a/GBwHlm7
however ICMP still works to that client.... even though i have it dropped on a wide rule with just "in", "drop", "icmp"
windows RDP also seems to be working, in general everything seems to be working fine. on the VM... even though input rule is default "drop"
it sort of seams like the firewall ain't properly loading or applying rules.
I tried a pve-firewall status & pve-firewall restart - without any success..
i'm facing some really basic issues related to firewall i think... i'm in the middle of trying to build up a firewall, but before even going any deeper i need to get basic things working and tested.
So here a basic example of things i can't the firewall to work with....
- DATACENTER, firewall enabled
Default input policy: DROP
Default output policy: ACCEPT
Rules:
1. allow traffic on vmbr0, port 8006 - looks to be working.
See picture if needed: https://imgur.com/a/BFABgbq
- NODE - firewall enabled
Rules:
1. no rules added here
See picture if needed: https://imgur.com/a/lqDF67u
- VM- firewall enabled
Default input policy: DROP
Default output policy: ACCEPT
rules:
1. added "in" "drop" "icmp" - https://imgur.com/a/fuBxwxb
See picture if needed: https://imgur.com/a/GBwHlm7
however ICMP still works to that client.... even though i have it dropped on a wide rule with just "in", "drop", "icmp"
windows RDP also seems to be working, in general everything seems to be working fine. on the VM... even though input rule is default "drop"
it sort of seams like the firewall ain't properly loading or applying rules.
I tried a pve-firewall status & pve-firewall restart - without any success..