[SOLVED] SDN wrt Microsegmentation

Diametric

New Member
Jun 19, 2024
3
0
1
I've been playing around with SDN with a goal to implement a form of microsegmentation and believe that what I'm after is not currently possible without some form of work around. (VMs with multiple NICs etc)

Is someone able to let me know if there is plans for the following on the horizon or if I've missed this functionality somewhere?

1. Route leaking between SDN zones or the ability to restrict communications between VNets within a zone.
2. In the case of route leaking between zones, some way to restrict communications between the zones to allow only specific traffic, possibly an extension of the firewall to be able to apply to a zone/VNet. Would be nice to be able to just point the firewall at two zones/VNets and allow/restrict traffic as required.

In general I'm after the ability to create a private subnet per VM/group of VMs and easily link as required to other private subnets.

Thanks in advance.
 
2. In the case of route leaking between zones, some way to restrict communications between the zones to allow only specific traffic, possibly an extension of the firewall to be able to apply to a zone/VNet. Would be nice to be able to just point the firewall at two zones/VNets and allow/restrict traffic as required.

This is something I'm currently exploring with the new nftables implementation, although I can give no guarantees on when this will land.
 
  • Like
Reactions: Diametric

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!