Proxmox Firewall: Locking Down Your Homelab at the Datacenter, Node, and VM Level
Proxmox ships with a real, iptables-backed firewall built into the platform, and most homelabs never turn it on. It’s not enabled by default at any level, so unless you’ve gone looking for it in the UI, there’s a good chance your VMs and containers are sitting behind nothing but whatever VLAN segmentation you’ve set up, if any. That’s often fine. It stops being fine the moment you’re running something internet-facing, or you want one VM to be reachable only from your management network and nowhere else, or a compromised guest shouldn’t be able to freely talk to everything else on its VLAN just because they share a broadcast domain. This is what the built-in firewall is actually for, and it’s worth understanding the shape of it before you flip it on. ...