Set-PveNodesQemuFirewallRules
Modify rule data.
API: PUT /nodes/{node}/qemu/{vmid}/firewall/rules/{pos}, Proxmox VE API viewer
Syntax
Section titled “Syntax”Set-PveNodesQemuFirewallRules [-PveTicket <PveTicket>] [-Action <string>] [-Comment <string>] [-Delete <string>] [-Dest <string>] [-Digest <string>] [-Dport <string>] [-Enable <int>] [-IcmpType <string>] [-Iface <string>] [-Log <string>] [-Macro <string>] [-Moveto <int>] -Node <string> [-Pos <int>] [-Proto <string>] [-Source <string>] [-Sport <string>] [-Type <string>] -Vmid <int> [<CommonParameters>]Parameters
Section titled “Parameters”| Parameter | Type | Required | Description |
|---|---|---|---|
-PveTicket |
PveTicket |
No | Ticket data connection. |
-Action |
string |
No | Rule action (‘ACCEPT’, ‘DROP’, ‘REJECT’) or security group name. |
-Comment |
string |
No | Descriptive comment. |
-Delete |
string |
No | A list of settings you want to delete. |
-Dest |
string |
No | Restrict packet destination address. This can refer to a single IP address, an IP set (‘+ipsetname’) or an IP alias definition. You can also specify an address range like ‘20.34.101.207-201.3.9.99’, or a list of IP addresses and networks (entries are separated by comma). Please do not mix IPv4 and IPv6 addresses inside such lists. |
-Digest |
string |
No | Prevent changes if current configuration file has a different digest. This can be used to prevent concurrent modifications. |
-Dport |
string |
No | Restrict TCP/UDP destination port. You can use service names or simple numbers (0-65535), as defined in ‘/etc/services’. Port ranges can be specified with ‘\d+:\d+’, for example ‘80:85’, and you can use comma separated list to match several ports or ranges. |
-Enable |
int |
No | Flag to enable/disable a rule. |
-IcmpType |
string |
No | Specify icmp-type. Only valid if proto equals ‘icmp’ or ‘icmpv6’/‘ipv6-icmp’. |
-Iface |
string |
No | Network interface name. You have to use network configuration key names for VMs and containers (‘net\d+’). Host related rules can use arbitrary strings. |
-Log |
string |
No | Log level for firewall rule. Values: emerg, alert, crit, err, warning, notice, info, debug, nolog. |
-Macro |
string |
No | Use predefined standard macro. |
-Moveto |
int |
No | Move rule to new position <moveto>. Other arguments are ignored. |
-Node |
string |
Yes | The cluster node name. |
-Pos |
int |
No | Update rule at position <pos>. |
-Proto |
string |
No | IP protocol. You can use protocol names (‘tcp’/‘udp’) or simple numbers, as defined in ‘/etc/protocols’. |
-Source |
string |
No | Restrict packet source address. This can refer to a single IP address, an IP set (‘+ipsetname’) or an IP alias definition. You can also specify an address range like ‘20.34.101.207-201.3.9.99’, or a list of IP addresses and networks (entries are separated by comma). Please do not mix IPv4 and IPv6 addresses inside such lists. |
-Sport |
string |
No | Restrict TCP/UDP source port. You can use service names or simple numbers (0-65535), as defined in ‘/etc/services’. Port ranges can be specified with ‘\d+:\d+’, for example ‘80:85’, and you can use comma separated list to match several ports or ranges. |
-Type |
string |
No | Rule type. Values: in, out, forward, group. |
-Vmid |
int |
Yes | The (unique) ID of the VM. |
Every parameter also binds by property name from the pipeline, so an object with node and vmid properties (the output of Get-PveGuest, for one) fills -Node and -Vmid. Without -PveTicket the cmdlet uses the last connection, see Connection.
Output
Section titled “Output”A PveResponse: the data returned by Proxmox VE is in .Response.data, the outcome in .IsSuccessStatusCode. See Results and Errors.