Which network ports are required

TCP only.
 
It’s always better to keep the port closed if possible. So better use VPN.

I don’t use VPN in that case but I opened the port only for specific source IP addresses (so only addresses of my Nodes). All other Source IPs are blocked by Firewall.
Maybe it will give you some idea.

Best regards
Floh
 
I don’t use VPN in that case but I opened the port only for specific source IP addresses (so only addresses of my Nodes). All other Source IPs are blocked by Firewall.
Ok so rather than letting the router perform the allow-list, you told the PVE firewall to perform this? I think I will simply let my router's firewall perform this.

Thanks Floh,
Tmanok
 
Last edited:
No, I have a dedicated machine as firewall (OPNsense) and Proxmox Backup Server is running as VM on my QNAP.
 
Last edited: