惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
Jina AI
Jina AI
博客园 - 叶小钗
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
T
Tailwind CSS Blog
博客园 - 【当耐特】
雷峰网
雷峰网
Last Week in AI
Last Week in AI
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 三生石上(FineUI控件)
A
About on SuperTechFans
博客园 - 司徒正美
酷 壳 – CoolShell
酷 壳 – CoolShell
I
InfoQ
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
Y
Y Combinator Blog
爱范儿
爱范儿
博客园 - 聂微东
美团技术团队
H
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Cisco Blogs
P
Proofpoint News Feed
S
SegmentFault 最新的问题
C
Cybersecurity and Infrastructure Security Agency CISA
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
Tor Project blog
I
Intezer
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
NISL@THU
NISL@THU
C
Check Point Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
L
LangChain Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
The Hacker News
The Hacker News
Microsoft Security Blog
Microsoft Security Blog
S
Secure Thoughts
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog

Proxmox Support Forum

[SOLVED] - Github Auth for Mirrors-Kernel Repo? [Automation] Mass migration tool for MS Win11/Server Proxmox GUI hang - not response is it possible to reject or quarantine spam based on conditions I set ? The PVENode task list in PVE9 is partially obscured due to the terminal font being too large. About 100% error reporting due to pveproxy.service hooks Kubernetes overlay networking breaks when upgrading from PVE 9.1 to PVE 9.2.3 Zentraler Speicher No space left on device Combine datastore and direct file archival to tape Kernel panic VFS: Unable to mount root fs on unknown-block (0,0) sobald ein 7.x Kernel verwendet wird. How to migrate disk of a VM from one ZFS to another Windows Server 2025 fails to boot after PVE 9.2 / Linux 7.0 Kernel upgrade Cannot Install Proxmox on T610 Poweredge with H700 PERC card sdn Config. gateway not reachable How to safely change domain/FQDN? Welche Filterquote erreicht ihr? NFS Share status unknown on 2 of 5 nodes Can't connect to PVE9 consoles [solved] Can't connect to PVE9 consoles [solved] [SOLVED] - Use secondary network for PVE commands Created cluster, one node storage gone BUG: proxmox mail gateway FROM = null bypass spam filtering Moving existing PBS from VMWare workstation to PVE cluster Does eBGP SDN fabric support external peering? Bug: PDM 1.1 not recognizing valid license status Proxmox GUI hang - not response PVE crashes unexpectedly Proxmox Backup Server 4.2 released! Advice ceph-osd crashes with kernel 6.17.2-1-pve on Dell system [META] Links on Proxmox Forum Website Hardwarer oder Software RAID Joining a cluster with already created guests VM PDM missing backup jobs from PVE / Log retention Remove VM.Monitor from all users/roles, PVE 9.2 Proxmox Freezing (new instalation) 9.2.2 - Intel 12700T No Web gui and random connection reset by peer [SOLVED] - i40e module for X710 Intel NIC Dutch Proxmox Day 2026 How pools use the space Corosync initiiert Reboot trotz Verfügbarkeit der Systeme Opt-in Linux 7.0 Kernel for Proxmox VE 9 available After PVE 8to9 upgrade, unable to check guest fs freeze status Problem with MegaRAID SAS3508 controller proxmox-kernel-7.0.2-6-pve failing network service Auto sync guest time after rollback of VM snapshot with RAM/state Broadcom BCM57504 (100G) bnxt_en TX timeout and NIC reset on Proxmox 8.1.5 — while BCM57414 (25G) works fine on same host QEMU 11.0 available on pve-test and pve-no-subscription as of now 350 MPM Solventless Lamination Machine for High-Speed Flexible Packaging Making sense of NVMe zfs and SMART errors [SOLVED] - PVE loses network connection after kernel upgrade to proxmox-kernel-7.0.0-3-pve [SOLVED] - Remove or reset cluster configuration. Proxmox 8.4.1 Fresh Install BCM57416 10G Ethernet Adapter Not Recognized PDM 1.1.1 unable to add AD realm with anonymous search [TUTORIAL] - Developer Workstation (Proxmox-VE 9) with cinnamon (LMDE7) SDN zone shows "pending" on peer nodes after node reboot (9.2.x) Cluster not quorate - extending auth key lifetime! Proxmox not rebooting properly (SOLVED) Proxmox 9 Stuck on loading initial ramdisk With new HA-Disarm Feature is there a Documentation for NUT Setup on Clusters? Proxmox 8.3 Installation Issue on ProLiant DL380 Gen9 Cluster networking setup LXC System images unavailable [SOLVED] - Fix: NVIDIA Drivers Failing after upgrade to Proxmox 9.2.2 (Kernel 7.0.2-6-pve) / NovaCore Conflict Install NUT directly on Proxmox VE and control guests from here driver usb for windows 7 System startup error and no network: Failed to start ifupdown2-pre.service - Helper to synchronize boot up for ifupdown. PBS backup space grow up constantly Proxmox Datacenter Manager 1.1 released! IPv4 not available in newly created VM Recommended Setup for Offsite Proxmox Backups? Hetzner Storage Box & Remote PBS Challenges duplicate, please delete this passthrought an USB device "by ID" to CT PDM Installer Freezes at 66% Tried PDM for the first time (version 1.1) - had issues PDM 1.1 automated install Suche Server-Provider für Proxmox connecting sdn to edge firewall SDN, IPAM & DHCP Migrating from read-only file system Ubuntu 26.04 installation fails for unknown reason Status Unbekannt nach Cluster Join Installing Proxmox Backup Server on Mac Mini (Late 2012) kernel 7.0 performance issue with zfs pools PVE becomes unreachable via ethernet but OS is running [SOLVED] - New 9.2 install - can't find 7.0.2-6-pve , not all the time [SOLVED] - Backup and dedupe a VM with LUKS Gibt es mit PVE 2.x ggf. Änderungen bei der RAM-Nutzung, bzw. deren Anzeige bei VMs? I need help for setting up backup solution Way more NAGware, very little functionality, bugs galore Root squashing virtiofsd with --uid-map Intel ixgbe Driver Update Fail Passkey Login (not 2FA) Roblox VM detection - can be overcome? [TUTORIAL] - ZFS-Autosnaptshot inkl. Rollback und Daten direkt recovern (Windows/Linux) How to stop PVE Kernel upgrade [SOLVED] - very long waiting to log in to lxc debian 11 ssh [TUTORIAL] - Configuring Fusion-Io (SanDisk) ioDrive, ioDrive2, ioScale and ioScale2 cards with Proxmox Increase maximum USB devices in vm.conf
Issue with SNAT on SDN configuration
invalid@exam · 2026-06-12 · via Proxmox Support Forum

Hello community,

We need an hand to solve an issue that is driving us crazy. Please help us to find the missing piece of the puzzle :)
We are unable to contact public hosts using HTTP and HTTPS from LXC containers, although DNS and ICMP work.

Our proxmox configuration
1 public ip on vmbr0
SDN -> zone CTs -> Vnet0 -> subnet 192.168.18.0/24 - gtw 192.168.18.1 - dhcp on .200-.250 - SNAT ON
Datacenter firewall ON without configured rules
Host firewall ON with these configured rules:
iifname "Vnet0" udp dport 53 ip daddr 192.168.18.1 accept
iifname "Vnet0" tcp dport 53 ip daddr 192.168.18.1 accept
iifname "Vnet0" udp sport 67-68 udp dport 67-68 accept
tcp dport 8006 accept
tcp dport 6922 accept
tcp dport 443 ip daddr 192.168.18.0/24 accept
tcp dport 80 ip daddr 192.168.18.0/24 accept

NFTABLES ON
Additional nftables routing entries, because we want the all incoming https and http traffic to go to HaProxy
table inet nat {
chain prerouting {
type nat hook prerouting priority dstnat; policy accept;
iifname "vmbr0" ip protocol tcp tcp dport 80 ip daddr PUBLICIP dnat ip to 192.168.18.10
iifname "vmbr0" ip protocol tcp tcp dport 443 ip daddr PUBLICIP dnat ip to 192.168.18.10
}

chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
ip daddr 192.168.18.0/24 return
ip saddr 192.168.18.0/24 masquerade
}
}

Firewall OFF for all lxc and VMs
FROM LXC "HA Proxy" eth0 bridge Vnet0 IP 192.168.0.10 -> all working as expected

Others LXC in the same Subnet are able to resolve DNS and make ICMP traffic trought the Vnet0 but all HTTP and HTTPS traffic don't work.

Following the tcpdump captured from the HOST for the traffic arriving from tha LXC with IP 192.168.18.58 trying to reach google.com - FAILED

LXC CT ~# curl -I https://google.com
.
HOST:
tcpdump -i Vnet0 host 192.168.18.58 -n
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on Vnet0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
12:26:16.491541 IP 192.168.18.58.46745 > 213.186.33.99.53: 37054+ A? google.com. (28)
12:26:16.491559 IP 192.168.18.58.46745 > 213.186.33.99.53: 61375+ AAAA? google.com. (28)
12:26:16.495699 IP 213.186.33.99.53 > 192.168.18.58.46745: 37054 6/0/0 A 142.251.110.101, A 142.251.110.100, A 142.251.110.138, A 142.251.110.113, A 142.251.110.139, A 142.251.110.102 (124)
12:26:16.495831 IP 213.186.33.99.53 > 192.168.18.58.46745: 61375 4/0/0 AAAA 2a00:1450:4001:c1f::71, AAAA 2a00:1450:4001:c1f::8b, AAAA 2a00:1450:4001:c1f::65, AAAA 2a00:1450:4001:c1f::8a (140)
12:26:16.495942 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:17.548699 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:18.572698 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:19.596684 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:20.620687 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:21.644685 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:23.692688 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:27.724696 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:35.852684 IP 192.168.18.58.59382 > 142.251.110.101.443: Flags , seq 207633860, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
^C
13 packets captured
13 packets received by filter
0 packets dropped by kernel

Following the tcpdump captured from the HOST for the traffic arriving from the LXC with IP 192.168.18.58 trying to reach a public FTP host - SUCCESS
tcpdump -i Vnet0 host 192.168.18.58 -n
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on Vnet0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
12:26:50.980959 IP 192.168.18.58.41764 > 213.186.33.99.53: 25955+ A? ftp.cluster128.hosting.ovh.net. (48)
12:26:50.980974 IP 192.168.18.58.41764 > 213.186.33.99.53: 59745+ AAAA? ftp.cluster128.hosting.ovh.net. (48)
12:26:51.011200 IP 213.186.33.99.53 > 192.168.18.58.41764: 25955 1/0/0 A 5.135.37.212 (64)
12:26:51.021123 IP 213.186.33.99.53 > 192.168.18.58.41764: 59745 0/1/0 (96)
12:26:51.021179 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags , seq 23797078, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 10], length 0
12:26:51.032576 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [S.], seq 604620498, ack 23797079, win 42340, options [mss 1460,nop,nop,sackOK,nop,wscale 9], length 0
12:26:51.032586 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags [.], ack 1, win 63, length 0
12:26:51.046155 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [P.], seq 1:82, ack 1, win 83, length 81: FTP: 220- ~~~ Welcome to OVH ~~~
12:26:51.046159 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags [.], ack 82, win 63, length 0
12:26:51.046171 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags [P.], seq 1:17, ack 82, win 63, length 16: FTP:
12:26:51.057398 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [.], ack 17, win 83, length 0
12:26:51.057694 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [P.], seq 82:124, ack 17, win 83, length 42: Password required
12:26:51.057703 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags [P.], seq 17:39, ack 124, win 63, length 22: FTP: PASS ftp@example.com
12:26:51.115508 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [.], ack 39, win 83, length 0
12:26:55.321924 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [P.], seq 124:157, ack 39, win 83, length 33: FTP: 530 Login authentication failed
12:26:55.321977 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags [F.], seq 39, ack 157, win 63, length 0
12:26:55.333438 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [P.], seq 157:170, ack 40, win 83, length 13: FTP: 530 Logout.
12:26:55.333452 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags [R], seq 23797118, win 0, length 0
12:26:55.334250 IP 5.135.37.212.21 > 192.168.18.58.49862: Flags [F.], seq 170, ack 40, win 83, length 0
12:26:55.334253 IP 192.168.18.58.49862 > 5.135.37.212.21: Flags [R], seq 23797118, win 0, length 0
12:26:56.332687 ARP, Request who-has 192.168.18.58 tell 192.168.18.1, length 28
12:26:56.332711 ARP, Reply 192.168.18.58 is-at bc:24:11:46:1f:0e, length 28
^C
22 packets captured
22 packets received by filter
0 packets dropped by kernel

Thank you!!