Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Eneko Lacunza
You can also setup iptables so that only your fixed IPs are allowed to port 8006 (and ssh port...) On 14/09/14 19:00, ad...@extremeshok.com wrote: You don't need a VPN Follow the guides on my site this will give you a secure and optimized proxmox. Set proxmox admin interface to only listen

Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Guy Plunkett
I would strongly suggest against this or indeed any way to put proxmox directly on the internet. The way I go about this would be to create a private network inside proxmox and host a real firewall system such as pfsense (pfsense.org) to front the internet and then use PPTP or OpenVPN to

Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Eneko Lacunza
Guy, so how do you connect if the Firewall VM is down? :) On 15/09/14 09:43, Guy Plunkett wrote: I would strongly suggest against this or indeed any way to put proxmox directly on the internet. The way I go about this would be to create a private network inside proxmox and host a real

Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Guy Plunkett
well yeah that's always a problem. :).. I also use zenoss core (zenoss.org) to monitor my systems. You can easily configure zenoss to monitor the firewall etc, and if it's down, you can have it connect to proxmox and restart it. Cheers, --Guy On 15 Sep 2014, at 08:51, Eneko Lacunza

Re: [PVE-User] Internet facing Proxmox

2014-09-14 Thread ad...@extremeshok.com
You don't need a VPN Follow the guides on my site this will give you a secure and optimized proxmox. Set proxmox admin interface to only listen locally (127.0.0.1) and connect via an ssh tunnel to port 8006. No offense, but this should be standard knowledge for an admin. Guides on