SDN (EVPN) + VM Firewall

nikordev

Member
Mar 7, 2022
9
1
8
33
Hello, i used EVPN to link a cluster VM. It's working, thanks ;)

But it ignores the VM firewall rules(

My test case from the guide https://pve.proxmox.com/pve-docs-6/chapter-pvesdn.html

I trying drop all in/out for vm1 (c001-vm101) and vm2 (c001-vm102) but they are ignoring the rules


1646694171918.png
1646694257912.png

Firewall rules c001-vm101 are similar to c001-vm102
Nodes have rules with accept all inputs/outputs

Is this the expected behavior?
If expected, what are the tricks to get around it?

My goal is to be able to control network interaction between virtual machines on the EVPN network.
 
Additional information:

Version: 7.1-10

Firewall enabled on all 3 levels (DC, Node, VM)

I have vm c001-vm100 with simple bridge interface (vmbr0) to vlan and firewall work without problem for it

Code:
sysctl -a |grep call
abi.vsyscall32 = 1
net.bridge.bridge-nf-call-arptables = 0
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
 
Hi,
I'm using evpn in production with firewall, I don't have any problem.

(I don't see why it shouldn't work, as the firewalling is done at bridge level, after the evpn).

Just to be sure:

- is the firewall checkbox enable on vm nic interface ?
- is the firewall enabled at datacenter level ?
 
- is the firewall checkbox enable on vm nic interface ?

Yes, it's not enabled o_O

I'm so dumb...:D

Sorry for my mistake

Everything is working fine now, thanks!
 
Last edited:
  • Like
Reactions: spirit

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!