<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Firewall on wgz.sh</title>
    <link>https://blog.wgz.sh/tags/firewall/</link>
    <description>Recent content in Firewall on wgz.sh</description>
    <generator>Hugo -- 0.153.1</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 26 Apr 2026 20:14:30 -0400</lastBuildDate>
    <atom:link href="https://blog.wgz.sh/tags/firewall/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Enabling Proxmox Firewall Rules for VMs</title>
      <link>https://blog.wgz.sh/posts/proxmox-firewall/</link>
      <pubDate>Sun, 26 Apr 2026 20:14:30 -0400</pubDate>
      <guid>https://blog.wgz.sh/posts/proxmox-firewall/</guid>
      <description>&lt;h2 id=&#34;intro&#34;&gt;Intro&lt;/h2&gt;
&lt;p&gt;In my homelab I&amp;rsquo;ve been tediously managing firewall rules using &lt;code&gt;ufw&lt;/code&gt;, &lt;code&gt;iptables&lt;/code&gt;, and &lt;code&gt;fail2ban&lt;/code&gt;. While this works well, I believe it&amp;rsquo;s overly complicated for my setup. This led me down the rabbit hole of how to implement firewall rules in Proxmox.&lt;/p&gt;
&lt;p&gt;Proxmox&amp;rsquo;s firewall is extremely competent, but it can be tricky as well.&lt;/p&gt;
&lt;p&gt;One thing I learned about Proxmox is that you need to make sure the firewall is enabled in multiple places. You have several layers of firewalling, one for the hosts, one for the VMs, and one for services running in VNETs. These firewall rules are backed by either &lt;code&gt;iptables&lt;/code&gt; or the more modern &lt;code&gt;nftables&lt;/code&gt; in the case of VNETs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Relocating My Homelab</title>
      <link>https://blog.wgz.sh/posts/colocating-my-homelab/</link>
      <pubDate>Sat, 05 Apr 2025 17:15:21 -0400</pubDate>
      <guid>https://blog.wgz.sh/posts/colocating-my-homelab/</guid>
      <description>&lt;p&gt;Hey all,&lt;/p&gt;
&lt;p&gt;I recently decided to purchase a dedicated server from &lt;a href=&#34;https://my.racknerd.com/&#34;&gt;RackNerd&lt;/a&gt; with the goal of hosting my homelab services remotely.&lt;/p&gt;
&lt;p&gt;Previously, I ran a high-availability Proxmox cluster out of my one-bedroom apartment in NYC, powered by a few Dell Optiplex 4090s. A few months ago, I moved into a new place and had to decommission that setup.&lt;/p&gt;
&lt;p&gt;Since my new setup is remote, it presented a few challenges:&lt;br&gt;
&lt;em&gt;How am I going to administer my lab? How can I secure it? What services will I host?&lt;/em&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
