hello all,
right now i have the configuration like in the attachment (the top Picture) and i want to optimize to the bottom part of the picture
New should be:
1. Hetzner does the Port Filtering (only the desired ports are opened)
2. Proxmox Host does the Country filter, and IDS
3. the opnFirewall does forwarding, HAProxy, SSLoffloading, Monitoring, etc.
for the sake of simplicity. some questions plz
1. i will do the host firewall on Proxmox host, but the issue is that ipset cant handle big lists of IPs. i had previously a server with ipset and big lists, its possible and works like a carm. in proxmox the file crashes. does anybody has the same issue ?
2. how would look like a iptable firewall rule to forward traffic from vmbr0 to the SDN, EXT1 ?
right now i have the configuration like in the attachment (the top Picture) and i want to optimize to the bottom part of the picture
New should be:
1. Hetzner does the Port Filtering (only the desired ports are opened)
2. Proxmox Host does the Country filter, and IDS
3. the opnFirewall does forwarding, HAProxy, SSLoffloading, Monitoring, etc.
for the sake of simplicity. some questions plz
1. i will do the host firewall on Proxmox host, but the issue is that ipset cant handle big lists of IPs. i had previously a server with ipset and big lists, its possible and works like a carm. in proxmox the file crashes. does anybody has the same issue ?
2. how would look like a iptable firewall rule to forward traffic from vmbr0 to the SDN, EXT1 ?