Strange behavior of the VM-Firewall-Setting

roli8200

Member
Feb 7, 2020
17
0
21
49
Just spent hours to debug a very strange behavior of the
firewall checkbox in the VM network device configuration.

When I check (enable) the firewall checkbox, the vm
has full network access (no port is blocked), everything works fine.

When I uncheck (disable) the firewall checkbox,
the vm has no network access at all.

From my point of view, the checkbox does the exact opposite of what it should do.
Can someone explain the exact function / behaviour of this checkbox?

I cannot find any difference in ebtables, iptables, bridge or tap configuration between
the box checked or not. Not even the kvm command line to start the vm is diffrent.
I could also not find any information in the documentation about the function of this checkbox.
For sample, the directory /etc/pve/firewall from the documentation does not exist on any node.
Non of the informations in the documentation seems to match the configuration, files or settings found
on the a installed system in any way.
 

Attachments

  • Firewall-proxmox.PNG
    Firewall-proxmox.PNG
    12.1 KB · Views: 5
the firewall check on the nic, only create a new bridge (fwbr...), between your vm and the vmbr bridge. (don't known why it change your network behaviour).

After that, you need to enable firewall in firewall options in the vm. (and the iptables will be created)
 
>the firewall check on the nic, only create a new bridge (fwbr...), between your vm and the vmbr bridge.
>(don't known why it change your network >behaviour).
This is the strange thing. There is absolutely no difference in bridge configuration on that host (which runs the vm)
with or without the firewall bridge checked. All the bridge configuration is exactly the same with or without this box checked.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!