hello guys
some questions related to firewall (because i put my cluster already offline of a wrong firewall rule)
i have proxmox, 4 nodes, with 2 sdn 2 vnets, in one of the vnets are 2 vlan networks (no subnet - it doesnt work, i dont know why)
suppose i have a webserver in vnet1/vlan20, the other is 21 (just to isolate it)
- the new vnet firewall i can block whats going in and out of the vnets ? correct ? so i would set there a rule Webserver allowed
- for the VM firewall i set rules in the vnet (if traffic stays internal( for instance the webserver connects to a database, i would create 2 rules, for for each to grand access ? correct so far
- the datacenter firewall protects the Host itself. would it be ok to implement my own firewall rules, based on iptables, not over the proxmox ? i have a complex rule set with ipset and a lot of features.
- the node firewall - which ports are a must for ceph, ha, corosync, webinterface, etc --- - that the nodes works
for vnet and vm firewall = how can i create templates ?
regards
some questions related to firewall (because i put my cluster already offline of a wrong firewall rule)
i have proxmox, 4 nodes, with 2 sdn 2 vnets, in one of the vnets are 2 vlan networks (no subnet - it doesnt work, i dont know why)
suppose i have a webserver in vnet1/vlan20, the other is 21 (just to isolate it)
- the new vnet firewall i can block whats going in and out of the vnets ? correct ? so i would set there a rule Webserver allowed
- for the VM firewall i set rules in the vnet (if traffic stays internal( for instance the webserver connects to a database, i would create 2 rules, for for each to grand access ? correct so far
- the datacenter firewall protects the Host itself. would it be ok to implement my own firewall rules, based on iptables, not over the proxmox ? i have a complex rule set with ipset and a lot of features.
- the node firewall - which ports are a must for ceph, ha, corosync, webinterface, etc --- - that the nodes works
for vnet and vm firewall = how can i create templates ?
regards