Firewall Rules for a Proxmox Host

The Proxmox web interface and SSH limited to admin addresses. Rules here cover the host itself; VM traffic is not affected. The services are already ticked: add your own addresses and pick your firewall.

  • Free
  • No Sign-Up
  • Runs in Your Browser

Services to Open

Check Before You Apply

SSH is open to the whole internet. Limit it to your own addresses if they are fixed.

A database or admin port is open to everyone. Add the addresses that need it under Allow Admin Ports From.

These rules replace the existing input rules. Check nothing else (Docker, fail2ban, the Proxmox firewall) manages this server's firewall first.

/etc/nftables.conf

#!/usr/sbin/nft -f
# /etc/nftables.conf: generated at frabs.net/tools/firewall-rule-generator/
flush ruleset

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;

    ct state established,related accept
    ct state invalid drop
    iif "lo" accept
    ip protocol icmp icmp type { echo-request, destination-unreachable, time-exceeded } limit rate 10/second accept
    ip6 nexthdr icmpv6 accept  # IPv6 needs ICMPv6 for neighbour discovery
    tcp dport 22 accept  # SSH
    tcp dport 8006 accept  # Proxmox Web UI
  }

  chain forward {
    type filter hook forward priority 0; policy accept;
  }

  chain output {
    type filter hook output priority 0; policy accept;
  }
}

# Apply:  nft -f /etc/nftables.conf
# Keep at boot:  systemctl enable nftables

Firewall Rule Generator

Proxmox Host firewall

Openproxmox
DefaultDrop everything else coming in
OutboundAllowed
SSHLimit to your addresses

The Proxmox web interface and SSH limited to admin addresses. Rules here cover the host itself; VM traffic is not affected.

Apply the rules from a session you can recover: a provider console, or with a scheduled rollback, so a mistake cannot lock you out.

Questions

Which ports should a proxmox host open?
The Proxmox web interface and SSH limited to admin addresses. Rules here cover the host itself; VM traffic is not affected.

Firewalls stop traffic coming in

Frabs stops the abuse going out: spam, scans and floods from any VM, caught by behaviour, not by port.