Skip to content

New-PveClusterFirewallGroupsIdx

Create new rule.

API: POST /cluster/firewall/groups/{group}, Proxmox VE API viewer

New-PveClusterFirewallGroupsIdx
[-PveTicket <PveTicket>]
-Action <string>
[-Comment <string>]
[-Dest <string>]
[-Digest <string>]
[-Dport <string>]
[-Enable <int>]
-Group <string>
[-IcmpType <string>]
[-Iface <string>]
[-Log <string>]
[-Macro <string>]
[-Pos <int>]
[-Proto <string>]
[-Source <string>]
[-Sport <string>]
-Type <string>
[<CommonParameters>]
Parameter Type Required Description
-PveTicket PveTicket No Ticket data connection.
-Action string Yes Rule action (‘ACCEPT’, ‘DROP’, ‘REJECT’) or security group name.
-Comment string No Descriptive comment.
-Dest string No Restrict packet destination address. This can refer to a single IP address, an IP set (‘+ipsetname’) or an IP alias definition. You can also specify an address range like ‘20.34.101.207-201.3.9.99’, or a list of IP addresses and networks (entries are separated by comma). Please do not mix IPv4 and IPv6 addresses inside such lists.
-Digest string No Prevent changes if current configuration file has a different digest. This can be used to prevent concurrent modifications.
-Dport string No Restrict TCP/UDP destination port. You can use service names or simple numbers (0-65535), as defined in ‘/etc/services’. Port ranges can be specified with ‘\d+:\d+’, for example ‘80:85’, and you can use comma separated list to match several ports or ranges.
-Enable int No Flag to enable/disable a rule.
-Group string Yes Security Group name.
-IcmpType string No Specify icmp-type. Only valid if proto equals ‘icmp’ or ‘icmpv6’/‘ipv6-icmp’.
-Iface string No Network interface name. You have to use network configuration key names for VMs and containers (‘net\d+’). Host related rules can use arbitrary strings.
-Log string No Log level for firewall rule. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog.
-Macro string No Use predefined standard macro.
-Pos int No Update rule at position <pos>.
-Proto string No IP protocol. You can use protocol names (‘tcp’/‘udp’) or simple numbers, as defined in ‘/etc/protocols’.
-Source string No Restrict packet source address. This can refer to a single IP address, an IP set (‘+ipsetname’) or an IP alias definition. You can also specify an address range like ‘20.34.101.207-201.3.9.99’, or a list of IP addresses and networks (entries are separated by comma). Please do not mix IPv4 and IPv6 addresses inside such lists.
-Sport string No Restrict TCP/UDP source port. You can use service names or simple numbers (0-65535), as defined in ‘/etc/services’. Port ranges can be specified with ‘\d+:\d+’, for example ‘80:85’, and you can use comma separated list to match several ports or ranges.
-Type string Yes Rule type. Values: in, out, forward, group.

Every parameter also binds by property name from the pipeline, so an object with node and vmid properties (the output of Get-PveGuest, for one) fills -Node and -Vmid. Without -PveTicket the cmdlet uses the last connection, see Connection.

A PveResponse: the data returned by Proxmox VE is in .Response.data, the outcome in .IsSuccessStatusCode. See Results and Errors.