Proxmox firewall showing drop logs for another VM

Blackworm

New Member
May 21, 2024
4
1
3
Hello everyone,

I searched the forum but couldn't find a similar post...

I have started to set up firewalls on my VMs. Simply, I found myself seeing some very strange logs.

To explain, I have 3 VMs
Code:
HostA = a simple router. ip = 10.0.0.1
HostB = a server hosting a web service on 443 port. ip = 10.0.0.10
HostC = another server. ip = 10.0.0.20

I've enabled the firewall only on HostC for now, with INPUT POLICY DROP and a rule to allow SSH. VMs HostA and HostB do not have the firewall enabled.

However, on the HostC firewall logs I get this :
Code:
policy DROP: IN=fwbr2020i0 OUT=fwbr2020i0 PHYSIN=fwln2020i0 PHYSOUT=tap2020i0 MAC=aa:bb:cc:dd:ee:ff:ab:bc:cd:de:ef:fg:08:00 SRC=10.0.0.1 DST=10.0.0.10 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=15878 DF PROTO=TCP SPT=47156 DPT=443 SEQ=3062970246 ACK=0 WINDOW=32120 SYN

I checked for duplicate MACs and found that all my network cards have a unique MAC address. For your information, I'm running Virtual Environment 8.2.2. The strange thing is that I do have access to the 10.0.0.10:443 web server.

It's as if the packets were misrouted from time to time


Thanks to those who will take the time to read me
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!