# Example cluster-wide firewall rules for /etc/pve/firewall/cluster.fw # # Stage 1 (single host, current): only the mgmt IPSET applies. Applied # automatically by scripts/deploy-firewall.sh, which fills in . # # Stage 2 (future cluster/Ceph): the corosync and Ceph rules below are # commented out placeholders. Uncomment and fill in / # when nodes 2/3 join and those networks actually exist - # leaving them active on a single node with no corosync/Ceph traffic is # just dead config, and a literal `` is invalid syntax if # left uncommented and unfilled. # # Copy to /etc/pve/firewall/cluster.fw and edit before enabling (or use # scripts/deploy-firewall.sh). [OPTIONS] enable: 1 policy_in: DROP policy_out: ACCEPT [IPSET mgmt] [RULES] # Web UI + SSH only from the management network IN ACCEPT -source +mgmt -p tcp -dport 8006 -log nolog IN ACCEPT -source +mgmt -p tcp -dport 22 -log nolog # ICMP echo (ping) from the management network - diagnostic convenience # only, nothing else depends on it. Without this, policy_in DROP silently # eats ping while SSH/web UI keep working - looks like an outage during # troubleshooting when the host is actually fine. See # docs/06-pve-test-wifi-network.md for a case this caused real confusion. IN ACCEPT -source +mgmt -p icmp -icmp-type echo-request -log nolog # Stage 2: Corosync (cluster quorum) - uncomment once node 2/3 join and # the corosync network/VLAN exists. # IN ACCEPT -source -p udp -dport 5404:5405 -log nolog # Stage 2: Ceph (uncomment once Ceph is live; ports: mon 3300,6789, # osd/mgr/mds 6800-7300) # IN ACCEPT -source -p tcp -dport 3300 -log nolog # IN ACCEPT -source -p tcp -dport 6789 -log nolog # IN ACCEPT -source -p tcp -dport 6800:7300 -log nolog