Suggestions for the pve-firewall script.

proxnoci

Member
Jan 15, 2023
43
5
8
1) Add a macro for a PVE-Cluster allowing internal traffic between nodes (corosync...)
2) Add a macro for PVE management (allow access to port 8006 ...)
3) Make the macro list editable / external from the PVE::firewall scripting.
4) create a pve-nodes ipset and add alias for each of the nodes, also add those aliasses to the pve-nodes ipset.
5) create a ceph-nodes ipset containing on cluster cept-nodes, with aliasses, like in 4
6) allow for an external list of ceph nodes in case they are there.
a) clients
b) external servers referenced from proxmox or nodes there.
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!