Hello,
I'm quite new to Proxmox and there is something I don't get.
I've just done some firewall rules (filtering public IPs who can access a specific VM on specifics ports). But when I attempt to test unauthorized IPs, I can access my resources (which isn't supposed to be normal).
When I see the logs, I see that the IP initiating the request is my PVE's IP. Am I missing something ? Does PVE translate requests ? Or is it something in my iptables ?
Here are my logs :
103 6 tap103i0-IN 18/Aug/2023:10:08:42 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5175 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:42 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5176 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:42 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5177 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:44 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5178 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:45 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5179 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:45 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5180 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:49 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5181 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:49 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5182 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:57 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5183 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:57 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5184 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:31 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46753 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:31 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46754 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:31 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46755 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:32 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46756 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:34 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46757 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:34 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46758 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:38 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46759 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:38 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46760 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:46 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46761 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:46 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46762 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
I'm quite new to Proxmox and there is something I don't get.
I've just done some firewall rules (filtering public IPs who can access a specific VM on specifics ports). But when I attempt to test unauthorized IPs, I can access my resources (which isn't supposed to be normal).
When I see the logs, I see that the IP initiating the request is my PVE's IP. Am I missing something ? Does PVE translate requests ? Or is it something in my iptables ?
Here are my logs :
103 6 tap103i0-IN 18/Aug/2023:10:08:42 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5175 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:42 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5176 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:42 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5177 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:44 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5178 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:45 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5179 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:45 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5180 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:49 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5181 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:49 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5182 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:57 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5183 DF PROTO=TCP SPT=61858 DPT=8443 SEQ=2822076442 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:08:57 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:e8:39:35:a6:fd:ac:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=127 ID=5184 DF PROTO=TCP SPT=61859 DPT=8443 SEQ=869446092 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:31 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46753 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:31 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46754 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:31 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46755 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:32 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46756 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:34 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46757 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:34 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46758 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:38 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46759 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:38 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46760 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:46 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46761 DF PROTO=TCP SPT=62302 DPT=8443 SEQ=181136419 ACK=0 WINDOW=64860 SYN
103 6 tap103i0-IN 18/Aug/2023:10:20:46 +0200 policy DROP: IN=fwbr103i0 OUT=fwbr103i0 PHYSIN=fwln103i0 PHYSOUT=tap103i0 MAC=b6:8d:06:62:46:41:00:90:7f:d9:28:dc:08:00 SRC=10.50.1.1 DST=10.50.1.5 LEN=52 TOS=0x00 PREC=0x00 TTL=124 ID=46762 DF PROTO=TCP SPT=62303 DPT=8443 SEQ=433260555 ACK=0 WINDOW=64860 SYN