I'm trying to get familiar with the Proxmox Firewall. I'm having the following problem:
The only way it could get DHCP on vmbr0 working is by adding a very broad firewall rule "source: ANY, destination: ENY, macro: forwarded DHCP = ALLOW". I'm concerned that this is too broad: If by accident a DHCP server starts to listen on any interface (including bridge devices) that DHCP traffic now gets through.
Is there an elegant way to only allow the DHCP traffic on vmbr0?
(Thanks for any feedback!)
- I have a dhcp server running on the Proxmox host, listening on vmbr0 (on the host's IP configured on vmbr0)
- the Proxmox firewall is enabled on all levels (datacenter, host, vm) with default input: drop / default output: allow
The only way it could get DHCP on vmbr0 working is by adding a very broad firewall rule "source: ANY, destination: ENY, macro: forwarded DHCP = ALLOW". I'm concerned that this is too broad: If by accident a DHCP server starts to listen on any interface (including bridge devices) that DHCP traffic now gets through.
Is there an elegant way to only allow the DHCP traffic on vmbr0?
(Thanks for any feedback!)