[PVE-User] Proxmox in DMZ

lst_hoe02 at kwsoft.de lst_hoe02 at kwsoft.de
Fri Nov 18 13:32:07 CET 2011


we are testing Proxmox and would like to get some Input about securing  
the HW Node. We like to limit ssh, the webinterface and deny the rest  
with ip(6)tables which should be trouble free. What i'm unsure is

- Would this break anything from Proxmox point of view?

- What ports/connections/directions would be needed for clustering  
with a server outside the DMZ?

- Is it possible to install our own SSL/TLS certificate instead the  
self created?

There will be no NFS used on this node so maybe it would be save to  
turn off portmapper/statd?

Many Thanks


