🌐 Network configuration
ItemValueUsage
Bridgevmbr0VM ↔ LAN bridge
NATOptionalVM network isolation
SSHPort 22Secure admin
Proxmox firewallEnabledPer-VM rules
🔌 Service ports
ServicePortAccessStatus
Proxmox WebUI8006LAN (HTTPS)✅ Active
SSH22LAN✅ Active
Ollama API11434Local VM✅ Active
Open WebUI3000LAN🟡 Planned
PostgreSQL / pgvector5432VM215 (local VM)✅ Active
Qdrant (fallback)6333Local VM🟡 Fallback
n8n5678LAN🟡 Planned
To distinguish: this table describes the direct exposure of application ports on the local network — deliberately not opened for Open WebUI and n8n. Both services are nonetheless already published over HTTPS for external access, via the VM200 reverse proxy (see Reverse Proxy), which relays the request without exposing the internal port.
🔒 SSH hardening
bash
# /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300

# Générer une clé SSH
ssh-keygen -t ed25519 -C 'portfolio-ia'

# Copier la clé
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@proxmox-host

# Vérifier les règles firewall
iptables -L -n -v

Related pages

References & Sources

CategoryResourceURL
Official documentationProxmox VE — Network Configurationpve.proxmox.com/wiki/Network_Configuration
Official documentationProxmox VE — Firewallpve.proxmox.com/wiki/Firewall
Official documentationOpenSSH — Manualopenssh.com/manual
LicenseProxmox VE — AGPLv3 · OpenSSH — licence BSDgnu.org/licenses/agpl-3.0
Content of this pageShared under CC BY-SA 4.0creativecommons.org/licenses/by-sa/4.0