Comprehensive data protection for all workloads
Post Reply
mikeely
Veteran
Posts: 287
Liked: 96 times
Joined: Nov 07, 2016 7:39 pm
Full Name: Mike Ely
Contact:

Feature Request: host firewall control on VSA

Post by mikeely »

While I appreciate that the firewall rules on the VSA are already pretty restrictive, we would really appreciate some deeper level of control. For example, if the only available place to put an EM server is on a public IP (as is, sadly, the current case for me), it would be great to restrict access to those ports which are kept open to a set of networks. Our case is odd, we'd need a /27 here, a /29 there, and so on. Safe bet other customers have similar needs, even for non-routable addresses where legal compliance issues are in play.

I think it would be pretty easy from a UI design perspective and probably easy to do programmatically - firewalld gives me hives as does every other attempt to do Windows-like behavior on Linux but I'm sure somebody there knows how to make it work.
'If you truly love Veeam, then you should not let us do this :D' --Gostev, in a particularly Blazing Saddles moment
vnikiforov
Veeam Software
Posts: 173
Liked: 60 times
Joined: Aug 17, 2022 5:03 am
Full Name: Vladimir Nikiforov
Location: Romania
Contact:

Re: Feature Request: host firewall control on VSA

Post by vnikiforov »

Hello, Mike,

Thank you, very interesting suggestion. Are we basically talking about a UI to control firewalld from Host Management Console?
---
BR,
Vladimir
Veeam Software
mikeely
Veteran
Posts: 287
Liked: 96 times
Joined: Nov 07, 2016 7:39 pm
Full Name: Mike Ely
Contact:

Re: Feature Request: host firewall control on VSA

Post by mikeely »

I suppose it would make the most sense to control it from the Host Management Console - let the security officer account manage the security features. Although maybe it shouldn't be in the Host Management Console, as that 100% requires web access over port 10443 and if there's one rule about firewalls that's consistent across all implementations it's that people will inevitably firewall themselves out of their system. This configuration needs to be at least capable of being reached from the physical host in some supportable way and I haven't yet seen how to access Host Management from that route.

In terms of function it should be pretty simple: firewalld already has the required ports configured, so the only function here would be to limit which IP addresses or CIDR ranges could access the system, very simple.

Here's an example of what I mean:
Image

Add that along with needed documentation and helptext, feature added.
'If you truly love Veeam, then you should not let us do this :D' --Gostev, in a particularly Blazing Saddles moment
vnikiforov
Veeam Software
Posts: 173
Liked: 60 times
Joined: Aug 17, 2022 5:03 am
Full Name: Vladimir Nikiforov
Location: Romania
Contact:

Re: Feature Request: host firewall control on VSA

Post by vnikiforov » 1 person likes this post

Hello, Mike,

Thank you for the details. I have checked internally, and we already have this feature in the plans for future versions. I can't provide any ETAs at this point, though.
---
BR,
Vladimir
Veeam Software
mikeely
Veteran
Posts: 287
Liked: 96 times
Joined: Nov 07, 2016 7:39 pm
Full Name: Mike Ely
Contact:

Re: Feature Request: host firewall control on VSA

Post by mikeely »

Great. Hopefully soon!
'If you truly love Veeam, then you should not let us do this :D' --Gostev, in a particularly Blazing Saddles moment
Loosus456
Influencer
Posts: 12
Liked: 3 times
Joined: Sep 29, 2021 12:22 pm
Full Name: Jason
Contact:

[MERGED] Is it possible to adjust inbound firewall rules on VSA?

Post by Loosus456 »

In the Veeam Software Appliance, is it possible to adjust host-maintained inbound firewall rules?

We have a firewall appliance that does the majority of our filtering, but we like to put even more strict and granular firewall rules on our hosts -- and we usually replicate what our firewall appliance is doing on the hosts so that allowing a port inbound means changing rules both on the (a) host and (b) firewall appliance. This ensures that if a misconfiguration occurs on the firewall, the host can still protect itself.

But I am not seeing an interface where we can manage firewall rules in VSA. Maybe I am missing it?

At least for our own use case, such an interface could be fairly simple, just allowing us to have a list of the major inbound services and indicate their associated source-IP addresses in CIDR notation. Example: management subnet(s) for IT workstations to manage VSA, subnet(s) for repositories, etc.

Outbound rules would be nice too, but inbound is the bigger one.
vnikiforov
Veeam Software
Posts: 173
Liked: 60 times
Joined: Aug 17, 2022 5:03 am
Full Name: Vladimir Nikiforov
Location: Romania
Contact:

Re: Feature Request: host firewall control on VSA

Post by vnikiforov »

Hello, Jason,

Your question was merged with the previous topic on that subject.
Your request is noted and added to the internal feature request tracker.
Please find my answer above in the thread - the feature is planned already.
---
BR,
Vladimir
Veeam Software
Post Reply

Who is online

Users browsing this forum: alexsene59, Amazon [Bot], jackal2001, jbender81, Mildur and 560 guests