Skip to content

Set-PveNodesLxcFirewallRules

Modify rule data.

API: PUT /nodes/{node}/lxc/{vmid}/firewall/rules/{pos}, Proxmox VE API viewer

Set-PveNodesLxcFirewallRules
[-PveTicket <PveTicket>]
[-Action <string>]
[-Comment <string>]
[-Delete <string>]
[-Dest <string>]
[-Digest <string>]
[-Dport <string>]
[-Enable <int>]
[-IcmpType <string>]
[-Iface <string>]
[-Log <string>]
[-Macro <string>]
[-Moveto <int>]
-Node <string>
[-Pos <int>]
[-Proto <string>]
[-Source <string>]
[-Sport <string>]
[-Type <string>]
-Vmid <int>
[<CommonParameters>]
Parameter Type Required Description
-PveTicket PveTicket No Ticket data connection.
-Action string No Rule action (‘ACCEPT’, ‘DROP’, ‘REJECT’) or security group name.
-Comment string No Descriptive comment.
-Delete string No A list of settings you want to delete.
-Dest string No Restrict packet destination address. This can refer to a single IP address, an IP set (‘+ipsetname’) or an IP alias definition. You can also specify an address range like ‘20.34.101.207-201.3.9.99’, or a list of IP addresses and networks (entries are separated by comma). Please do not mix IPv4 and IPv6 addresses inside such lists.
-Digest string No Prevent changes if current configuration file has a different digest. This can be used to prevent concurrent modifications.
-Dport string No Restrict TCP/UDP destination port. You can use service names or simple numbers (0-65535), as defined in ‘/etc/services’. Port ranges can be specified with ‘\d+:\d+’, for example ‘80:85’, and you can use comma separated list to match several ports or ranges.
-Enable int No Flag to enable/disable a rule.
-IcmpType string No Specify icmp-type. Only valid if proto equals ‘icmp’ or ‘icmpv6’/‘ipv6-icmp’.
-Iface string No Network interface name. You have to use network configuration key names for VMs and containers (‘net\d+’). Host related rules can use arbitrary strings.
-Log string No Log level for firewall rule. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog.
-Macro string No Use predefined standard macro.
-Moveto int No Move rule to new position <moveto>. Other arguments are ignored.
-Node string Yes The cluster node name.
-Pos int No Update rule at position <pos>.
-Proto string No IP protocol. You can use protocol names (‘tcp’/‘udp’) or simple numbers, as defined in ‘/etc/protocols’.
-Source string No Restrict packet source address. This can refer to a single IP address, an IP set (‘+ipsetname’) or an IP alias definition. You can also specify an address range like ‘20.34.101.207-201.3.9.99’, or a list of IP addresses and networks (entries are separated by comma). Please do not mix IPv4 and IPv6 addresses inside such lists.
-Sport string No Restrict TCP/UDP source port. You can use service names or simple numbers (0-65535), as defined in ‘/etc/services’. Port ranges can be specified with ‘\d+:\d+’, for example ‘80:85’, and you can use comma separated list to match several ports or ranges.
-Type string No Rule type. Values: in, out, forward, group.
-Vmid int Yes The (unique) ID of the VM.

Every parameter also binds by property name from the pipeline, so an object with node and vmid properties (the output of Get-PveGuest, for one) fills -Node and -Vmid. Without -PveTicket the cmdlet uses the last connection, see Connection.

A PveResponse: the data returned by Proxmox VE is in .Response.data, the outcome in .IsSuccessStatusCode. See Results and Errors.