Sounds like you are using Basic zone (with possibly improper IP/network
setup). Can you confirm/expain your networking/zone setup?

Best,

On Fri, Sep 18, 2026 at 4:38 PM Drew Weaver <[email protected]> wrote:

> Hello,
>
> Our one real requirement for the network operation for this project is
> basic network filtering so that if for example someone just assigns the IP
> address of the gateway for the VLAN's subnet to their VM's vNIC it doesn't
> break everything.
>
> The problems we noticed with our original PoC:
>
> We were planning on using firewalld to protect the management IPs on the
> hypervisors but we noticed that the only way we could get the guest VM
> networking to function is to disable firewalld.
> If we tried pinging an IP address that was assigned to a guest VM which is
> on a completely different network entirely the management NIC IP would just
> reply back with "filtered" until firewalld was disabled.
>
> We also noticed that the SystemVMs by default create a "defacto bridge"
> between the public/guest network by having one NIC in each of these
> networks. This is undesirable for us so I am trying to find an alternative.
>
> The questions are:
>
> Is it expected that having firewalld running would make it impossible to
> route traffic to the guestVM network or did I just not find the right
> kernel tuning/routing/firewalld setting to make it work?
>
> If you can use firewalld to protect the management NIC IP address does
> that interfere with the basic network filtering I mentioned as a
> requirement for this?
>
> Is there a way to put the "public" vNIC for the system VMs in another
> VLAN/subnet other than the pool that the guest VMs use if so does anyone
> know how to facilitate this?
>
> Our new PoC we are planning will use local storage on the HVs only and
> there will be 2x1G NICs [bond0] and 2x10G NICs [bond1]
>
> Cloudbr0 [bond0] native VLAN will be the actual "management" network, and
> then if it's possible the "public network for the System VMs" will be just
> a trunked vlan to the bond.
> Cloudbr1 [bond1] will just have the guest VM network trunked to the
> guestVM network
>
> Does this seem like a workable configuration?
>
> Thanks for your time.
> -Drew
>
>
>
>
>
>
>
>
>
>
>
>

-- 

Andrija Panić

Reply via email to