Hi, a security group I set up is blocking and logging some traffic that doesn't make sense to me, I'm wondering if anyone knows why its happening.
The source seems to be 1.1.1.1 and destination is my phone. My router is a separate device and DHCP is also from the router, so I don't understand why its appearing on the PVE firewall. I also don't understand why 1.1.1.1 which is probably cloudflare has incoming traffic to a device on my network via port 443 lol
The internal_only security group is applied to some of my virtual machines/containers, not sure how its affecting traffic that doesn't interact with proxmox
The source seems to be 1.1.1.1 and destination is my phone. My router is a separate device and DHCP is also from the router, so I don't understand why its appearing on the PVE firewall. I also don't understand why 1.1.1.1 which is probably cloudflare has incoming traffic to a device on my network via port 443 lol
The internal_only security group is applied to some of my virtual machines/containers, not sure how its affecting traffic that doesn't interact with proxmox
Code:
pvefw logger
0 6 GROUP-internal_only-IN 29/Aug/2022:02:08:03 +0800 IN=fwbr209i0 OUT=fwbr209i0 PHYSIN=fwln209i0 PHYSOUT=veth209i0 MAC=<mac> SRC=1.1.1.1 DST=192.168.0.103 LEN=79 TOS=0x00 PREC=0x00 TTL=60 ID=16427 DF PROTO=TCP SPT=443 DPT=60430 SEQ=37333883 ACK=678819274 WINDOW=4 ACK PSH
0 6 GROUP-internal_only-IN 29/Aug/2022:02:08:03 +0800 IN=fwbr201i0 OUT=fwbr201i0 PHYSIN=fwln201i0 PHYSOUT=veth201i0 MAC=<mac> SRC=1.1.1.1 DST=192.168.0.103 LEN=79 TOS=0x00 PREC=0x00 TTL=60 ID=16427 DF PROTO=TCP SPT=443 DPT=60430 SEQ=37333883 ACK=678819274 WINDOW=4 ACK PSH
0 6 GROUP-internal_only-IN 29/Aug/2022:02:08:03 +0800 IN=fwbr206i0 OUT=fwbr206i0 PHYSIN=fwln206i0 PHYSOUT=veth206i0 MAC=<mac> SRC=1.1.1.1 DST=192.168.0.103 LEN=79 TOS=0x00 PREC=0x00 TTL=60 ID=16427 DF PROTO=TCP SPT=443 DPT=60430 SEQ=37333883 ACK=678819274 WINDOW=4 ACK PSH
0 6 GROUP-internal_only-IN 29/Aug/2022:02:08:03 +0800 IN=fwbr205i0 OUT=fwbr205i0 PHYSIN=fwln205i0 PHYSOUT=tap205i0 MAC=<mac> SRC=1.1.1.1 DST=192.168.0.103 LEN=79 TOS=0x00 PREC=0x00 TTL=60 ID=16427 DF PROTO=TCP SPT=443 DPT=60430 SEQ=37333883 ACK=678819274 WINDOW=4 ACK PSH
0 6 GROUP-internal_only-IN 29/Aug/2022:02:08:03 +0800 IN=fwbr204i0 OUT=fwbr204i0 PHYSIN=fwln204i0 PHYSOUT=veth204i0 MAC=<mac> SRC=1.1.1.1 DST=192.168.0.103 LEN=79 TOS=0x00 PREC=0x00 TTL=60 ID=16427 DF PROTO=TCP SPT=443 DPT=60430 SEQ=37333883 ACK=678819274 WINDOW=4 ACK PSH