Set-PveNodesFirewallOptions
Set Firewall options.
API: PUT /nodes/{node}/firewall/options, Proxmox VE API viewer
Syntax
Section titled “Syntax”Set-PveNodesFirewallOptions [-PveTicket <PveTicket>] [-Delete <string>] [-Digest <string>] [-Enable <bool>] [-LogLevelForward <string>] [-LogLevelIn <string>] [-LogLevelOut <string>] [-LogNfConntrack <bool>] [-Ndp <bool>] [-NfConntrackAllowInvalid <bool>] [-NfConntrackHelpers <string>] [-NfConntrackMax <int>] [-NfConntrackTcpTimeoutEstablished <int>] [-NfConntrackTcpTimeoutSynRecv <int>] [-Nftables <bool>] -Node <string> [-Nosmurfs <bool>] [-ProtectionSynflood <bool>] [-ProtectionSynfloodBurst <int>] [-ProtectionSynfloodRate <int>] [-SmurfLogLevel <string>] [-TcpFlagsLogLevel <string>] [-Tcpflags <bool>] [<CommonParameters>]Parameters
Section titled “Parameters”| Parameter | Type | Required | Description |
|---|---|---|---|
-PveTicket |
PveTicket |
No | Ticket data connection. |
-Delete |
string |
No | A list of settings you want to delete. |
-Digest |
string |
No | Prevent changes if current configuration file has a different digest. This can be used to prevent concurrent modifications. |
-Enable |
bool |
No | Enable host firewall rules. |
-LogLevelForward |
string |
No | Log level for forwarded traffic. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog. |
-LogLevelIn |
string |
No | Log level for incoming traffic. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog. |
-LogLevelOut |
string |
No | Log level for outgoing traffic. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog. |
-LogNfConntrack |
bool |
No | Enable logging of conntrack information. |
-Ndp |
bool |
No | Enable NDP (Neighbor Discovery Protocol). |
-NfConntrackAllowInvalid |
bool |
No | Allow invalid packets on connection tracking. |
-NfConntrackHelpers |
string |
No | Enable conntrack helpers for specific protocols. Supported protocols: amanda, ftp, irc, netbios-ns, pptp, sane, sip, snmp, tftp. |
-NfConntrackMax |
int |
No | Maximum number of tracked connections. |
-NfConntrackTcpTimeoutEstablished |
int |
No | Conntrack established timeout. |
-NfConntrackTcpTimeoutSynRecv |
int |
No | Conntrack syn recv timeout. |
-Nftables |
bool |
No | Enable nftables based firewall (tech preview) |
-Node |
string |
Yes | The cluster node name. |
-Nosmurfs |
bool |
No | Enable SMURFS filter. |
-ProtectionSynflood |
bool |
No | Enable synflood protection. |
-ProtectionSynfloodBurst |
int |
No | Synflood protection rate burst by ip src. |
-ProtectionSynfloodRate |
int |
No | Synflood protection rate syn/sec by ip src. |
-SmurfLogLevel |
string |
No | Log level for SMURFS filter. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog. |
-TcpFlagsLogLevel |
string |
No | Log level for illegal tcp flags filter. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog. |
-Tcpflags |
bool |
No | Filter illegal combinations of TCP flags. |
Every parameter also binds by property name from the pipeline, so an object with node and vmid properties (the output of Get-PveGuest, for one) fills -Node and -Vmid. Without -PveTicket the cmdlet uses the last connection, see Connection.
Output
Section titled “Output”A PveResponse: the data returned by Proxmox VE is in .Response.data, the outcome in .IsSuccessStatusCode. See Results and Errors.