Closed mbrav closed 2 months ago
this is a read-only mirror of our source code. please see our community forum and bug tracker for reporting issues.
the new firewall does not support legacy aliases/ipsets (without a prefix like dc/
or guest/
). either wait for a fixed version, or edit your firewall settings once for each config file to trigger a read/modify/write cycle that adds those prefixes :)
Hi, very excited for the new PVE 8.2 Firewall based on nftables and written in Rust! Went ahead and upgraded PVE to 8.2, enabled nftables (tech preview) Yes in Web UI then the FW rules stopped working.
It seems that proxmox-firewall does not support alias resolution 😿 .
Here is the service output:
To investigate further, I ran the binary with full backtrace:
Output:
As it turns out,
pc_nic1
is an IP alias configured through Proxmox (more specifically, it was provisioned with Terraform, but lets stay on topic 😃), whichproxmox-firewall
does not resolve.Will probably get Rusty over the weekend and dable with the code to see if I can get aliases working 🦀