Three Firewall Levels in Proxmox VE
The Proxmox VE firewall works on top of iptables/nftables and is configured at three levels at once: datacenter, node, and individual virtual machine or container. Datacenter rules apply to every node in the cluster, node rules apply to a specific server's traffic, and VM rules apply only to that machine's network interfaces.
This hierarchy is convenient: common security rules are set once at the datacenter level, while targeted restrictions go on the VM level. The final behavior of a packet is defined by the sum of rules from all three levels, so before enabling the firewall you should know what is already configured where.
How to Enable the Firewall on the Datacenter and Node
Enabling happens in Datacenter → Firewall → Options: the enable parameter is switched to Yes. The same must be done in the Firewall section of each node — otherwise the datacenter rules will not apply to that server's traffic.
Before enabling, be sure to add a rule that allows access to the web interface on port 8006 and SSH on port 22 from your working addresses. Otherwise, after the default DROP policy kicks in, the management panel becomes unreachable. It is also worth protecting the panel with two-factor authentication.
Security Group Rules: Creation and Application
A Security Group is a named set of rules that can be applied to several nodes or VMs at once. The group is created in Datacenter → Firewall → Security Groups and then attached to the target object in one line.
| Field | Example value | Meaning |
|---|---|---|
| Direction | in | inbound traffic to the object |
| Action | ACCEPT | allow the packet |
| Protocol | tcp | restriction by protocol |
| Dest. port | 443 | destination port |
- Create a group with a clear name, for example
web-servers. - Add ACCEPT rules for the needed ports and a DROP rule for everything else.
- Attach the group to a VM or node through the Insert button in that object's Firewall section.
Firewall for a Specific VM or Container
Individual rules are set on the Firewall tab of the VM or LXC container itself. Enable the firewall for the machine and add only the ports that are actually needed — for example 80 and 443 for a web server, and block everything else with the default DROP policy.
cat /etc/pve/firewall/100.fw
[OPTIONS]
enable: 1
[RULES]
IN ACCEPT -p tcp -dport 80
IN ACCEPT -p tcp -dport 443
The same tab offers anti-spoofing options: MAC Filter checks that the VM sends packets only from its own MAC address, and IP Filter does the same for its own IP addresses. Access to firewall settings should be limited through roles and ACLs, so that only administrators can change the rules.
IP Sets for Groups of Addresses
An IPSet groups a list of IP addresses or subnets under one name and lets you reference them in rules instead of listing every address. This is convenient for a list of office IPs or monitoring addresses.
cat /etc/pve/firewall/cluster.fw
[IPSET management]
203.0.113.10
203.0.113.0/28
[RULES]
IN ACCEPT -p tcp -dport 22 -source +management
The +management entry in a rule references an IPSet with that name. When the list of addresses changes, you only need to edit one IPSet — every rule that references it updates automatically.
How to Test the Rules Without Locking Yourself Out
Before enabling a strict DROP policy, test access through a backup channel: IPMI, the hypervisor's web console, or physical access to the server. If you accidentally lock yourself out of SSH and the web interface, you can restore access through the node console with the pve-firewall stop command, which temporarily stops applying the rules.
After every change, check the module status with pve-firewall status and review the log in Firewall → Log — it shows which packets were dropped and by which rule.
Checklist for Safe Firewall Configuration
- A rule allowing ports 8006 and 22 is added before enabling the default DROP.
- The firewall is enabled on both the datacenter and every node.
- Security Groups are created for groups of servers instead of duplicating rules.
- VMs with public services expose only the ports they actually need.
- A backup access channel exists in case of a mistake in the rules.
The firewall complements network isolation at the bridge level: the basic principles of network separation are described in the article on network bridges and VLANs.