I would like to secure a proxmox cluster where the nodes have public IP addresses and there is no separate firewall in front.What would be the best way to proceed?jinjer
I would like to secure a proxmox cluster where the nodes have public IP addresses and there is no separate firewall in front.What would be the best way to proceed?jinjer
This is a very good setup. On top of it, the hosting provider must have a good DDOS protection, otherwise, despite the firewall mitigation rules, a flood could block the public network, the cluster nodes fail to communicate and trigger false positive reboots.Simply configure iptables on cluster nodes. Allow only ip address and ports that you need for your customers and everything else drop. Of course, you will allow full communications between cluster nodes. Outside world will see only allowed services.
I got proxmox box on public ip for years and only working thing from outside is ssh on non-standart port allowed only from specific ip. Everything else like mail services are redirected inside the virtuals.
We use essential cookies to make this site work, and optional cookies to enhance your experience.