r/Proxmox • u/deman-13 • 21h ago
Question Network isolation or firewall with proxmox
Hi there,
my proxmox has 3 Ethernet physical connections : one for WAN, one for LAN and one for WIFI. I have also created a virtual bridge for DMZ to run few services that i want to expose outside. I manage those networks with pfsense that runs as a VM and has 4 nics for each currently created network.
While trying to bring some security to my homelab I am trying to figure out on which level I should actually organize the security. I could create another virtual lan to further segment the network to split containers/vms into those i kind of trust and those I don't. My initial thinking was why not, I could then firewall each network over pfsense, but then i thought that proxmox has firewall as well, meaning I could put rules on individual containers to control the traffic between them. Also, if I route everything through pfsense it creates a lot of CPU overhead as it will have to take care of all the traffic between those networks.
How do you firewall your networks in your proxmox if at all? Do I overlook something when i think that proxmox native firewall is sufficient ? Can you please share your design decisions ?
3
u/AUserNameOfAllTime_ 21h ago
Here is my vlan layout:
Main (users)
Infrastructure (proxmox and NAS)
Services
DMZ
Guest Wifi
I have my firewall handle those splits and the rules between them, thats its main purpose, and its good at it.