-
mikeely
- Veteran
- Posts: 287
- Liked: 96 times
- Joined: Nov 07, 2016 7:39 pm
- Full Name: Mike Ely
- Contact:
Feature Request: host firewall control on VSA
While I appreciate that the firewall rules on the VSA are already pretty restrictive, we would really appreciate some deeper level of control. For example, if the only available place to put an EM server is on a public IP (as is, sadly, the current case for me), it would be great to restrict access to those ports which are kept open to a set of networks. Our case is odd, we'd need a /27 here, a /29 there, and so on. Safe bet other customers have similar needs, even for non-routable addresses where legal compliance issues are in play.
I think it would be pretty easy from a UI design perspective and probably easy to do programmatically - firewalld gives me hives as does every other attempt to do Windows-like behavior on Linux but I'm sure somebody there knows how to make it work.
I think it would be pretty easy from a UI design perspective and probably easy to do programmatically - firewalld gives me hives as does every other attempt to do Windows-like behavior on Linux but I'm sure somebody there knows how to make it work.
'If you truly love Veeam, then you should not let us do this
' --Gostev, in a particularly Blazing Saddles moment
-
vnikiforov
- Veeam Software
- Posts: 173
- Liked: 60 times
- Joined: Aug 17, 2022 5:03 am
- Full Name: Vladimir Nikiforov
- Location: Romania
- Contact:
Re: Feature Request: host firewall control on VSA
Hello, Mike,
Thank you, very interesting suggestion. Are we basically talking about a UI to control firewalld from Host Management Console?
Thank you, very interesting suggestion. Are we basically talking about a UI to control firewalld from Host Management Console?
---
BR,
Vladimir
Veeam Software
BR,
Vladimir
Veeam Software
-
mikeely
- Veteran
- Posts: 287
- Liked: 96 times
- Joined: Nov 07, 2016 7:39 pm
- Full Name: Mike Ely
- Contact:
Re: Feature Request: host firewall control on VSA
I suppose it would make the most sense to control it from the Host Management Console - let the security officer account manage the security features. Although maybe it shouldn't be in the Host Management Console, as that 100% requires web access over port 10443 and if there's one rule about firewalls that's consistent across all implementations it's that people will inevitably firewall themselves out of their system. This configuration needs to be at least capable of being reached from the physical host in some supportable way and I haven't yet seen how to access Host Management from that route.
In terms of function it should be pretty simple: firewalld already has the required ports configured, so the only function here would be to limit which IP addresses or CIDR ranges could access the system, very simple.
Here's an example of what I mean:

Add that along with needed documentation and helptext, feature added.
In terms of function it should be pretty simple: firewalld already has the required ports configured, so the only function here would be to limit which IP addresses or CIDR ranges could access the system, very simple.
Here's an example of what I mean:

Add that along with needed documentation and helptext, feature added.
'If you truly love Veeam, then you should not let us do this
' --Gostev, in a particularly Blazing Saddles moment
-
vnikiforov
- Veeam Software
- Posts: 173
- Liked: 60 times
- Joined: Aug 17, 2022 5:03 am
- Full Name: Vladimir Nikiforov
- Location: Romania
- Contact:
Re: Feature Request: host firewall control on VSA
Hello, Mike,
Thank you for the details. I have checked internally, and we already have this feature in the plans for future versions. I can't provide any ETAs at this point, though.
Thank you for the details. I have checked internally, and we already have this feature in the plans for future versions. I can't provide any ETAs at this point, though.
---
BR,
Vladimir
Veeam Software
BR,
Vladimir
Veeam Software
-
mikeely
- Veteran
- Posts: 287
- Liked: 96 times
- Joined: Nov 07, 2016 7:39 pm
- Full Name: Mike Ely
- Contact:
Re: Feature Request: host firewall control on VSA
Great. Hopefully soon!
'If you truly love Veeam, then you should not let us do this
' --Gostev, in a particularly Blazing Saddles moment
-
Loosus456
- Influencer
- Posts: 12
- Liked: 3 times
- Joined: Sep 29, 2021 12:22 pm
- Full Name: Jason
- Contact:
[MERGED] Is it possible to adjust inbound firewall rules on VSA?
In the Veeam Software Appliance, is it possible to adjust host-maintained inbound firewall rules?
We have a firewall appliance that does the majority of our filtering, but we like to put even more strict and granular firewall rules on our hosts -- and we usually replicate what our firewall appliance is doing on the hosts so that allowing a port inbound means changing rules both on the (a) host and (b) firewall appliance. This ensures that if a misconfiguration occurs on the firewall, the host can still protect itself.
But I am not seeing an interface where we can manage firewall rules in VSA. Maybe I am missing it?
At least for our own use case, such an interface could be fairly simple, just allowing us to have a list of the major inbound services and indicate their associated source-IP addresses in CIDR notation. Example: management subnet(s) for IT workstations to manage VSA, subnet(s) for repositories, etc.
Outbound rules would be nice too, but inbound is the bigger one.
We have a firewall appliance that does the majority of our filtering, but we like to put even more strict and granular firewall rules on our hosts -- and we usually replicate what our firewall appliance is doing on the hosts so that allowing a port inbound means changing rules both on the (a) host and (b) firewall appliance. This ensures that if a misconfiguration occurs on the firewall, the host can still protect itself.
But I am not seeing an interface where we can manage firewall rules in VSA. Maybe I am missing it?
At least for our own use case, such an interface could be fairly simple, just allowing us to have a list of the major inbound services and indicate their associated source-IP addresses in CIDR notation. Example: management subnet(s) for IT workstations to manage VSA, subnet(s) for repositories, etc.
Outbound rules would be nice too, but inbound is the bigger one.
-
vnikiforov
- Veeam Software
- Posts: 173
- Liked: 60 times
- Joined: Aug 17, 2022 5:03 am
- Full Name: Vladimir Nikiforov
- Location: Romania
- Contact:
Re: Feature Request: host firewall control on VSA
Hello, Jason,
Your question was merged with the previous topic on that subject.
Your request is noted and added to the internal feature request tracker.
Please find my answer above in the thread - the feature is planned already.
Your question was merged with the previous topic on that subject.
Your request is noted and added to the internal feature request tracker.
Please find my answer above in the thread - the feature is planned already.
---
BR,
Vladimir
Veeam Software
BR,
Vladimir
Veeam Software
Who is online
Users browsing this forum: alexsene59, Amazon [Bot], jackal2001, jbender81, Mildur and 560 guests