The documentation here: https://openvz.org/Common_Networking_HOWTOs#Venet
states:
Second (related) question:
Is there any way a venet IP could conflict with an IP outside of the Proxmox infrastructure[1]? It's been suggested that I shouldn't use 10.10.10.xxx addresses since they are routable on our LAN. My response was that venet NICs are essentially firewalled from the LAN. Who's correct?
[1] I understand that if ip-forwarding and masquerading are enabled then we'd essentially have a NAT, but the IPs would still be isolated from the LAN, right?
states:
Why would the host be able to ping the venet? I thought the idea of a venet was to provide connectivity between CTs but not between external networks?After [adding a venet] the host should be able to ping the VE.
Second (related) question:
Is there any way a venet IP could conflict with an IP outside of the Proxmox infrastructure[1]? It's been suggested that I shouldn't use 10.10.10.xxx addresses since they are routable on our LAN. My response was that venet NICs are essentially firewalled from the LAN. Who's correct?
[1] I understand that if ip-forwarding and masquerading are enabled then we'd essentially have a NAT, but the IPs would still be isolated from the LAN, right?