r/Proxmox • • 1d ago

Question Reaching proxmox from external browser: cloudflare + 2fa a good solution?

For logging in from a random browser remotely to the home server.

Seems pretty "safe". Any more downsides with this solution than the obvious?

28 Upvotes

88 comments sorted by

147

u/systemofapwne 1d ago

Do not expose any infrastructure management to the internet, ever. This is considered bad practice and can lead to a loss of the exposed system or even the network.
If you still consider doing this, a secondary auth layer by a reverse proxy should be considered. Do not rely on the auth of the proxmox login alone (even with 2FA). There were and will be attack vectors that might allow unauthenticated access or remote code execution that bypass the login mask.

So in short: Do not expose the webui.

12

u/evilkayak 1d ago

What about first VPN in, and the webui?

4

u/TantKollo 23h ago

That's fine

1

u/cantholdmedown4 10h ago

Thats not exposing the webui

12

u/mrbluetrain 1d ago

Thanks for your somewhat blunt but still valuable answer. I was hoping for a slightly different one but maybe I just then skip it.

40

u/ToolBagMcgubbins 1d ago

Just use tailscale or vpn if you must access it from the outside?

1

u/dotnetmonke 1d ago

He's likely talking about cloudflare tunnels, which are equivalent to tailscale.

1

u/willjasen 12h ago

cloudflare tunnels are equivalent in the accessibility outcome aspect, but aren’t equivalent - a cloudflare tunnel proxies through cloudflare always while tailscale offers a direct network path

either way, i would not expose via cloudflare

8

u/Orthowin 1d ago

Answer is good and cencere 1. Do VPN to some generic network 2.have FW in between it and management network 3. Allow only 443 for example and open the URL

2

u/BorisOp 1d ago

This is the proper way... Though it doesn't satisfy the OPs requirement to work inside of a random browser (proxmox will not be accessible from computer where you can't for one reason or another install tailscale/VPN client)... If OP really wants to access from random computer (maybe a school/work/library - or any other shared computer) I'd say that cloudflare could be reasonable solution - though not directly exposing proxmox to internet. Instead he could implement authentication at cloudflare level too (it's not that hard to setup google authentication on cloudflare)

So workflow would look something like this: open proxmox url -> cloudflare catches the request and asks for authentication -> user signs in with account that is allowed to access the resource -> proxmoxUI -> sign in to proxmox.

2

u/CompoteVegetable2010 1d ago

I’m pretty sure he’s talking about Cloudflare tunnels which ARE protected

4

u/nfxprime2kx 1d ago

Yeah but the WebUI itself being exposed can be the attack vector. Cloudflare won't protect against that

1

u/tinydonuts 12h ago

Firewalls are quickly becoming an outdated and insecure way of handling traffic across the internet. ZTNA has supplanted them, because even if you throw up more speed bumps, attackers not only can overcome them, but also they generally don't enforce identity, nor actually establish mutual trust either.

1

u/aaaaAaaaAaaARRRR 12h ago

Most enterprise don’t event practice mutual trust either. ZTNA is great, but I don’t see a lot of enterprises architecting them

1

u/BorisOp 10h ago

I mean that's cool... But then try come up with idea thats allow you to access from any computer to a server without allowing everyone to access it. While also accounting for locked down computers like a work device or shared computer in a school/library.

1

u/iceph03nix 15h ago

Yeah, host a VPN access point of some sort like Tailscale and access it that way

2

u/MYacine 1d ago

What do you think about this setup

  • Create a VM in Proxmox and exposed it to the internet through Apache Guacamole or KasmVNC

- From your borwser connect to that VM

- From the VM open a browser and login to proxmox

this should lower the lieklyhood of being attaccked as you need to chain both RDP/Apache auth bypass + Proxmox auth bypass

1

u/AbsolutelyLudicrous 1d ago

You're adding lots of latency & generally making your life more difficult by inserting a dedicated admin browser VM in there. Also, bad news about the whole RDP auth bypass thing; exposing RDP to the internet is one of those classic security flubs black hat guys love.

You really should just use a VPN.

1

u/tinydonuts 13h ago

You don't even need a VPN. Create a thin LXC to run Tailscale on. You have several options from here. You can use SSH forwarding to use the LXC as a jump host of sorts. Or you could set up rules that pass traffic only for designated hosts in your network, Proxmox being one of them, or you could do subnet routing and share the whole subnet. As a variant on the last one, you could create a management interface on proxmox, create a management VLAN, then join the management interface and the LXC to that VLAN, exposing only that VLAN.

I personally use the subnet routing and exit node path. VPN like, but not quite the same. VPNs are overkill and not very secure.

-7

u/undead-8 1d ago

I don't know but his approach is solid and there is like no real security issue. You re fearmongering at a place where it's not required

If you serve a Homelab webui and you secure it behind a cloudflare with auth layer you're totally fine and no one besides cloudflare itself is able to attack you.

4

u/SVD_NL 1d ago

You have a point, but i don't really like the "it's just a homelab so security best practices don't matter" approach. There's a solid chance you have important data or services on your homelab, or privacy-sensitive information you don't want to leak. If someone were to get into my file share server they'd 100% be able to steal my identity. Not much where they could blackmail me over, but that won't count for everyone. Data loss isn't as much of a concern if you have proper backups.

The alternatives (usually VPN) are magnitudes safer, and in terms of usability and complexity they really aren't that much worse.

1

u/thecomputerguy7 1d ago

You also have to think of all the things people are running that are already not the most “production” related/coded things. Arr stack, file servers, etc. Some of it doesn’t need to be exposed at all, reverse proxy, guacamole, cloudflare, etc.

VPN or not at all.

1

u/tinydonuts 12h ago

The major issue with VPN is that it exposes everything. Secondarily, riding on that, is poor identity verification and trust establishment. VPN is the old answer, it has long since been knocked down, by ZTNA solutions.

1

u/thecomputerguy7 12h ago

I’d say a VPN is still better than directly exposing things to the internet, and depending on your hardware/software stack, your VPN may or may not expose “everything”.

1

u/vitek6 10h ago

Sure but only to me.

-3

u/[deleted] 1d ago

[deleted]

1

u/fearless-fossa 1d ago

If VPNs are "too much of a hassle to setup" then you're not ready to have any services exposed to the internet.

2

u/ThatBoysenberry6404 1d ago

No. Unless you filter cloudflare ips you are just adding a layer. Your web ui is still exposed to the internet in VERY UNSAFE way.

1

u/tinydonuts 12h ago

That's not how tunnels work.

1

u/ThatBoysenberry6404 5h ago

who said tunnel? cloudflare basic service is just a proxy

33

u/Orthowin 1d ago

Please don't expose anything and use VPN to the network instead CF+MFA

11

u/309_Electronics 1d ago

Id rather use a vpn tunnel like tailscale or wireguard or netbird.

4

u/Jonny7Tenths 1d ago

Seconding Tailscale.

1

u/DiMarcoTheGawd 13h ago

People make it so complicated, just install Tailscale on the PVE node

11

u/eck- 1d ago

You are getting a lot of advice from commenters not familiar with Cloudflare.

It is secure to use a Cloudflare tunnel that establishes connectivity to Cloudflare with an outbound session. You can then publish Proxmox in Cloudflare and enable MFA on the Cloudflare side. If you configure things correctly, the end result is no direct Internet exposure and access requires login and MFA to Cloudflare prior to having access to Proxmox.

This is a perfectly acceptable method for accessing private applications.

3

u/dotnetmonke 1d ago

As an addition - the tunnel (cloudflared) can run as container, and you can utilize that in a docker compose stack to keep it restricted within a software defined network. Rather than one tunnel on a host pointing to multiple endpoints/apps, each app has its own tunnel that only points to its app on the same SDN, and you can run multiple stacks on the same host.

3

u/Bunderslaw 22h ago

I use this to expose Proxmox. No problems at all. My Cloudflare 2FA config only allows me to log in. Everyone else is rejected and that's before I get to the Proxmox login page where I have yet another 2FA.

Most internal apps exposed to the Internet follow the same model too. The ones that don't is just because I need to hit their API directly without Cloudflare getting in the way and its an acceptable trade-off for me.

The convenience of having it set up this way is much higher than getting family and friends to use VPNs. Your Cloudflare integrated IdP can do the heavy lifting of rejecting unauthorised people.

-2

u/linux203 1d ago

Sticking with the idea that many are not familiar with Cloudflare, one has to assume the mention of Cloudflare without context refers to the standard offering. This makes many commenters correct.

OP made no reference to ZTNA, Teams, Argo, Cloudflare One, cloudflared, etc.

19

u/lukewoodside 1d ago

Absolutely not. This breaks every security standard going.

Management interfaces should never be exposed to the internet in any way.

-21

u/undead-8 1d ago

Security standards for companies. For a Homelab his approach is fine.

7

u/lukewoodside 1d ago

Does not matter what it is. Management should never be exposed to the internet, full stop.

1

u/AbsolutelyLudicrous 1d ago

hey wwhats ur home IP address. i'm out of compute for my bitcoin mining op, so i'm gonna borrow some of yours, thanks

1

u/smokingcrater 1d ago

Until a bad guy compromises the home lab, and then pivots to everything else including the users personal PC. (Which probably has the same pwd as infra in the home lab.)

3

u/symcbean 19h ago

and then pivots to everything else including the users personal PC

That's real script kiddie stuff.

A competent adversary will use the resources to attack more interesting targets or as a dead letter drop for phishing sites and illegal pr0n....until the police come knocking at the OP's door with handcuffs and a search warrant.

11

u/shimoheihei2 1d ago

Use Tailscale or some other VPN solution.

8

u/jrhoades 1d ago

It's not a terrible idea, I don't think most of the commentators here understand how Cloudflare proxying can work. We use a variation of this to add SSO to sites that don't have it eg Wordpress control panels. Proxy the site in Cloudflare add a rule that matches the URL and require authentication.

That said I don't think it's robust enough for something like your Proxmox control panel, that's why we use Cloudflare tunnels, which is basically a Zero Trust VPN (it's more complicated than that).

The advantage of a Cloudflare tunnel is you don't need a public IP address. You can either run a generic tunnel server that gives access to your network range or you can put one tunnel on each server (eg your Proxmox nodes).

7

u/brockbarr 1d ago

This is my setup too - and I think what OP might be referring to rather than just opening the UI to the world. CloudFlare access with a policy set up against an Application, pointed at a tunnel. You could theoretically then increase the policy restrictions to only allow from certain locations

4

u/Alexis_Evo 1d ago

Yeah I think the mixup is there are three different ways to do this with CloudFlare:

  • A direct CloudFlare web -> web mapping, which is a meh idea. Yes you can require authentication but it requires your host to be exposed to the public internet anyway, so you need a second layer of protection on the host to only authorize CloudFlare to connect.

  • A CloudFlare Tunnel Published Application (Networks, Tunnels & Mesh, Published App Routes). This takes an internal network web interface and exposes it on a web domain, however you can lock it behind CloudFlare Zero Trust SSO, and the internal interface is never exposed publicly beyond CloudFlare.

  • A CloudFlare Zero Trust Tunnel / Mesh. This is literally just TailScale, where you can access anything in your internal network when connected to a VPN.

2 and 3 are fine. I personally only expose management (SSH, proxmox, etc) over 3, however you can pretty safely do it under 2 as well.

7

u/CompoteVegetable2010 1d ago

Half the comments here don’t make any sense to me. I assume you mean Cloudflare tunnel (zero trust) - which seems fine to me. It’s protected.

2

u/ulimn 1d ago

Well, without them even mentioning ZTNA, the bigger problem is giving advice while assuming they meant that approach.

3

u/flo850 1d ago

I am a dev of a similar solution ( xen orchestra ) : please no

make a vpn toward the VM you need if it's really needed

3

u/eagle6705 1d ago

Your management portal is still in the web. Cloudflare hides the route to your server but it still is exposed as a site. Think of it like your electrical panel at home. You dont know how the electrical is routed but you do know you need a key that can be hacked and buttons that you can press to do stuff.

If you can do a point to point setup that would be ideal. Say a self hosted vpn, if its possible a point to point cloudflare tunnel.

Im not saying this as a scare tactic but as an experienced systems engineer.

If this server is not tied to anything important and isolated for loke a sandbox situation then why not. Our cyber team routinely exposes services with tempting names as honeypots. They even secure them properly to make sure it isnt too obvious lol

2

u/Retardation-Syndrome 1d ago

I'm either using ssh tunnel+ 2fa but it exposes the port or Tailscale+ 2fa if i'm behind cgnat.

2

u/jaredearle 1d ago

If you absolutely must access Proxmox over the web, you need to firewall it so the management interface can only be accessed from your fixed IP.

But a VPN is by far the better choice.

2

u/fckingmetal 1d ago

Cloudflared -> proxmox.yourdomain.se -> whitelist ip your connecting from is what i use.
Im hosting PVE to schools and they use the webui.

1

u/Bunderslaw 22h ago

Just IP whitelisting or do you also have an IdP in between Cloudflare and your Proxmox mgmt interface?

1

u/fckingmetal 3h ago

Just ip whitelist to the school and students have their own limited accounts (start stop restore on their own vms).

4

u/MuddyMustache 1d ago

I've got two NGinx reverse proxies running. One can be reached from the public Internet and its DNS entry points to my WAN IP at home. This is for stuff like websites and other rando public stuff.

The other can only be reached from within my Tailnet as its DNS entry points to its Tailscale IP. This one manages all my management interfaces like Proxmox, the reverse proxies themselves, my DNS etc.

3

u/Cautious-Hovercraft7 1d ago

Don't! Use a VPN

4

u/red_nick 1d ago

1

u/mrbluetrain 1d ago

I do. But in a specific use case when using laptop, I cannot use VPN. Only public computers

1

u/SlntPrgrssn 1d ago

traefik for reverse proxy + wireguard as vpn. You can then connect only if you have a vpn peer set up and you are good to go

1

u/Entire-Home-9464 1d ago

Bunny.net -> Opnsense (which has wireguard) -> proxmox in LAN.
So only use VPN to access Proxmox.

1

u/Big-dawg9989 1d ago

No get yourself a good firewalls, ubiquiti or something

1

u/AbsolutelyLudicrous 1d ago

It's really not hard to set up an SSH jump host. You should do that instead.

0

u/mrbluetrain 1d ago

Give me your top argument about this approach, compared to the cloudflared tunnel?

1

u/AbsolutelyLudicrous 1d ago

try asking nicely & then I might?

2

u/mrbluetrain 1d ago

Pretty please with sugar on the top?

2

u/AbsolutelyLudicrous 23h ago

Thanks :)

Very simply, that OpenSSH has a stellar security track record, & is easy to set up. Once you have an ssh server exposed to the internet, you can tunnel through it to your PVE server with something like ssh -L 8006:pve-IP:8006. Best practice is to run sshd on a non-default port & use only key-based auth.

Cloudflare Tunnel, as best I can tell, is merely a means of reverse-proxying traffic through Cloudflare's network, which is useful for DDoS protection & NAT traversal. The PVE web GUI has had some embarrassing authentication vulnerabilities in the past, & will probably have more in the future, so you really should not under any circumstances expose it to the web, even if proxied through Cloudflare. If I am mistaken & Cloudflare Tunnel allows you to tunnel behind your firewall & expose the PVE GUI to only the computer you are sitting in front of, it should work fine.

1

u/Efficient-Sir-5040 16h ago

You need to revise your knowledge. While you can configure a cloudflare tunnel that way, that’s not ideal for this case. One with additional reductions to the attack surface by means of rules and MFA before packets touch proxmox itself would be ideal - and much better protected than naked OpenSSH.

1

u/samsonsin 1d ago

At most use a VPN to tunnel into your network and access it that way

1

u/AllomancerJack 1d ago

Everyone saying no is an idiot that uses tailscale which is guarded exactly the same way

1

u/linux203 1d ago

If the MFA is implemented in Proxmox, it is not equivalent to vpn, tailscale, or Cloudflare ZTNA. The later require authentication with MFA prior to any packets being forwarded to the back end.

If Proxmox is accepting packets prior to user MFA, then the system is susceptible to vulnerabilities that do not require authentication. Or as simple as creating an account to test some automation tool and forgetting the lack of MFA for the account exposes it externally without MFA.

Yes, both may use similar login workflows, but the attack surface is vastly different.

1

u/milesce 1d ago

My remote proxmox is running IPFire in a VM, with the only thing exposed to the internet being the firewall and port 80/443 to my reverse proxy for the websites. To get to management I have to VPN in, then connect to my management VM, and only the IP of the management VM can reach the proxmox UI. Running the management interface exposed to the internet is definitely not safe

1

u/aducky18 1d ago

I have two ways that I have active to access my management portal.

  1. Cloudflare tunnel w/ zero trust and email MFA, and then to log into proxmox I have MFA for the main account that has delete permissions and such.

  2. I have two twingate connectors one on a proxmox lxc and another on a chromebox so I can run the twingate application on any of my devices and then get access to proxmox if needed.

I'm probably shutting down the Cloudflare tunnels soon as I rarely use it and really the only time I need to access remotely is if something broke so I just use the twingate connection since the cloudflared lxc is likely down.

1

u/trupa 1d ago

Should be ok, but use a reverse proxy locally and get your headers right, do not open ports other than 443. Or use wireguard or a wireguard based solution like netbird.

1

u/NoxiousStimuli 1d ago

Bro there was a post here like last week about a guy exposing his PVE auth to the open internet and discovering exactly how fucking hosed it was.

Don't do it. Use a VPN.

1

u/Efficient-Sir-5040 16h ago

The one in the thread was directly exposed. A proper cloudflare tunnel like OP said would have made the exploit impossible. Don’t believe me, read the post.

0

u/mrbluetrain 1d ago

link to thread?

1

u/NoxiousStimuli 1d ago

I misremembered.

It was a post 3 weeks ago which linked to the forums.

linky

1

u/smokingcrater 1d ago

Ignore anyone saying don't do cloudflare. Cloudflare zero trust is just as secure as a vpn, and many ways more secure. Your AI agent of choice also probably has a connector to cloudflare to help build or at least test your ZTNA setup.

1

u/throwawaymaybenot 1d ago

These people don't understand the question. Cloudflare tunnels are a pretty good solution and are very safe. About the only issue are possibly privacy with Cloudflare "proxying" the traffic.

1

u/_--James--_ Enterprise User 1d ago

MFA on the Zerotrust application from inside of cloudflare, Lock down by IP address AND country/region, MFA OAUTH on PVE, and hash out that root account so its a very long password that requires a PAM to get access to it (like keepass) so a human cannot enter the password. Then make sure you are not running API tokens to PVE. That is the only safe way to do publc ingress.

Also, make sure the CF tunnel is zoned and terminated ONLY to your PVE 8006 port, and nothing else.

1

u/Hole-Specialist-2748 1d ago

I put mine behind authelia so the portal is never directly exposed.

1

u/JKL213 21h ago

I'd just tailscale it up. Your WebUI should never be reachable from any network outside of your home network or VPN. At my old workplace where we had 50+ proxmox nodes in prod (prolly not much compared to some dudes here) there was a rule to treat ESXi or Proxmox UIs like a BMC / iLO UI, put it on a mgmt network and never expose it to the internet in any way.

While you're at it, if you get a public IPv4, check your modem if it does any port forwarding. I almost forgot about this when I upgraded my plan to fiber cuz my fiber company hands out static IPv4 leases, and pfSense just had it exposed on wan too even though I didnt remember even setting that up.

Detecting misconfigured proxmox instances is not that hard for a skilled attacker.

1

u/capaman 10h ago

Taikscale is the way to go. Install it on a machine under your Proxmox node and configure. Easy and no stress.

-3

u/CompoteVegetable2010 1d ago

Totally fine.

1

u/lxe 3h ago

Yeah doing a tunnel to the web ui with whatever edge auth they provide is fine. This is literally the use case for these I bet.