PVE 9.0.3 firewall does not work, but same configuration work well in PVE 8.4.14 & 8.2.4

gunterwa

Active Member
Apr 1, 2022
45
2
28
Hi,

I have two PVE clusters (PVE-A & PVE-B) running on 8.4.14 & 8.2.4 for more than 2 years (same configuration), a newly deployed PVE with PVE 9.0.3 reused the configuration of PVE-A & PVE-B. BUT the firewall does not work...

Config summary:

1. Enable FW on DC level with security-group;
2. Enable FW on physical host level with same security-group in step_1;
3. Enable FW (in "Option" menu) on VM&LXC level with white-list (ipset & fw entries)

trouble shooting summary (Per gemini suggestion):

1. Carefully check the configuration, make sure FW enabled on DC and host level; VM/LXC level, FW-->Option-->Enable FW, Input Policy default "DROP"....
2. I added two new entries in LXC FW entry then check on host "pve-firewall compile" can see the newly added ones. Yes, it did in my case, but still didn't work.

Any comments and suggestions will be highly appreciated!
 
What is the status of the firewall daemon?

Code:
systemctl status pve-firewall