Simple firewall configuration

Chrisuk1978

New Member
Sep 4, 2016
1
0
1
46
Hi all,

I am just getting started with Proxmox. I presently have a single node hosting only one container.

The container is running a PBX, for which I need to expose a single port to my provider (IAX2: 4569 UDP). Accepting the risks, in the first instance I would like the firewall running in the container app to manage to security. Once I have convinced myself of calls in and out I will add more security around the PVE side of the setup.

Presently I am attempting the following:

External (Hardware) Router
- Port forward 4569 UDP to 192.168.0.nnn

Datacenter Firewall:
- Input policy: ACCEPT
- Output policy: ACCEPT

Node Firewall:
- Disabled

LXC Container 101 Network:
- Firewall: Disabled

LXC Container 101 Firewall:
- Disabled
- Input policy: ACCEPT
- Output policy: ACCEPT

Container (Elastix) Firewall:
- Configured

I presume that the above settings, at least as far as PVE is concerned will permit bidirectional traffic to the container? Does a disabled firewall also automatically block the inbound traffic in my configuration above.

I can see that local network traffic is routed to the LXC container, and also the container can connect back to the provider on the outbound route, however inbound calls are not getting to where they need to be,

All firmware/softeware is updated to latest available (PVE 4.4, Elastix 2.5), etc.

Many thanks.

All best,
Chris.
 
Last edited:
External (Hardware) Router
- Port forward 4569 UDP to 192.168.0.nnn

Datacenter Firewall:
- Input policy: ACCEPT
- Output policy: ACCEPT

Node Firewall:
- Disabled

LXC Container 101 Network:
- Firewall: Disabled

LXC Container 101 Firewall:
- Disabled
- Input policy: ACCEPT
- Output policy: ACCEPT

Container (Elastix) Firewall:
- Configured

I presume that the above settings, at least as far as PVE is concerned will permit bidirectional traffic to the container?

Yes - since your Node Firewall is disabled there are no restrictions at all; even if you would enable it nothig will be blocked since you have set policies to ACCEPT.

Does a disabled firewall also automatically block the inbound traffic in my configuration above.

No - a disabled firewall is not active and blocks nothing. But if you mean "Input policy REJECT" (or "DROP"): all incoming traffic (excepted access to ssh and WEB GUI) to pve host will be blocked as soon as also in the host (Node) firewall is enabled
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!