KVM · Platform
Frabs for Proxmox VE
Frabs runs on each Proxmox VE node and watches every VM and container's outbound traffic on its own network interface, without touching the guests.
Proxmox VE
- Protects
- KVM virtual machines and LXC containers
- Recognised by
- The pve-manager package
- Watches
- tap<vmid>i<n> · veth<ctid>i<n>
- Panel links
- Open in Proxmox
How it works
How Frabs works on Proxmox VE
- 01
Install
One command as root on the server. It reads the setup without changing anything.
- 02
Recognise Proxmox VE
The pve-manager package tells the sensor which platform it is on.
- 03
Find every guest
Each VM's configuration in /etc/pve/qemu-server/<vmid>.conf, including its network devices and MAC addresses. Each container's configuration in /etc/pve/lxc/<ctid>.conf.
- 04
You confirm
You review what it will watch. Protection starts within 30 seconds of confirming.
Networking
What it watches, and what it leaves alone
tap<vmid>i<n>
One per VM network device, for example tap101i0
veth<ctid>i<n>
One per container network device, for example veth204i0
Bridges. The Linux bridges your guests attach to, such as vmbr0. Bridges with no guests on them are left alone.
How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.
An example plan
Get started
Install on Proxmox VE
On the server, as root
curl -fsSL https://install.frabs.net | sh -s -- --token frb_...
- Install once per Proxmox node; each node counts as one server
- Each interface is matched to its guest by MAC address
- VM pages link straight to the VM: Open in Proxmox
- Read the Install Guide
Questions
Is anything installed inside the VMs?
Does Frabs change my bridges or firewall?
What happens if I add a bridge or move guests?
What if the sensor stops?
Also supported