Skip to content

Set-PveNodesFirewallOptions

Set Firewall options.

API: PUT /nodes/{node}/firewall/options, Proxmox VE API viewer

Set-PveNodesFirewallOptions
[-PveTicket <PveTicket>]
[-Delete <string>]
[-Digest <string>]
[-Enable <bool>]
[-LogLevelForward <string>]
[-LogLevelIn <string>]
[-LogLevelOut <string>]
[-LogNfConntrack <bool>]
[-Ndp <bool>]
[-NfConntrackAllowInvalid <bool>]
[-NfConntrackHelpers <string>]
[-NfConntrackMax <int>]
[-NfConntrackTcpTimeoutEstablished <int>]
[-NfConntrackTcpTimeoutSynRecv <int>]
[-Nftables <bool>]
-Node <string>
[-Nosmurfs <bool>]
[-ProtectionSynflood <bool>]
[-ProtectionSynfloodBurst <int>]
[-ProtectionSynfloodRate <int>]
[-SmurfLogLevel <string>]
[-TcpFlagsLogLevel <string>]
[-Tcpflags <bool>]
[<CommonParameters>]
Parameter Type Required Description
-PveTicket PveTicket No Ticket data connection.
-Delete string No A list of settings you want to delete.
-Digest string No Prevent changes if current configuration file has a different digest. This can be used to prevent concurrent modifications.
-Enable bool No Enable host firewall rules.
-LogLevelForward string No Log level for forwarded traffic. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog.
-LogLevelIn string No Log level for incoming traffic. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog.
-LogLevelOut string No Log level for outgoing traffic. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog.
-LogNfConntrack bool No Enable logging of conntrack information.
-Ndp bool No Enable NDP (Neighbor Discovery Protocol).
-NfConntrackAllowInvalid bool No Allow invalid packets on connection tracking.
-NfConntrackHelpers string No Enable conntrack helpers for specific protocols. Supported protocols: amanda, ftp, irc, netbios-ns, pptp, sane, sip, snmp, tftp.
-NfConntrackMax int No Maximum number of tracked connections.
-NfConntrackTcpTimeoutEstablished int No Conntrack established timeout.
-NfConntrackTcpTimeoutSynRecv int No Conntrack syn recv timeout.
-Nftables bool No Enable nftables based firewall (tech preview)
-Node string Yes The cluster node name.
-Nosmurfs bool No Enable SMURFS filter.
-ProtectionSynflood bool No Enable synflood protection.
-ProtectionSynfloodBurst int No Synflood protection rate burst by ip src.
-ProtectionSynfloodRate int No Synflood protection rate syn/sec by ip src.
-SmurfLogLevel string No Log level for SMURFS filter. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog.
-TcpFlagsLogLevel string No Log level for illegal tcp flags filter. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog.
-Tcpflags bool No Filter illegal combinations of TCP flags.

Every parameter also binds by property name from the pipeline, so an object with node and vmid properties (the output of Get-PveGuest, for one) fills -Node and -Vmid. Without -PveTicket the cmdlet uses the last connection, see Connection.

A PveResponse: the data returned by Proxmox VE is in .Response.data, the outcome in .IsSuccessStatusCode. See Results and Errors.