🌐 Network configuration
| Item | Value | Usage |
|---|---|---|
| Bridge | vmbr0 | VM ↔ LAN bridge |
| NAT | Optional | VM network isolation |
| SSH | Port 22 | Secure admin |
| Proxmox firewall | Enabled | Per-VM rules |
🔌 Service ports
| Service | Port | Access | Status |
|---|---|---|---|
| Proxmox WebUI | 8006 | LAN (HTTPS) | ✅ Active |
| SSH | 22 | LAN | ✅ Active |
| Ollama API | 11434 | Local VM | ✅ Active |
| Open WebUI | 3000 | LAN | 🟡 Planned |
| PostgreSQL / pgvector | 5432 | VM215 (local VM) | ✅ Active |
| Qdrant (fallback) | 6333 | Local VM | 🟡 Fallback |
| n8n | 5678 | LAN | 🟡 Planned |
To distinguish: this table describes the direct exposure of application ports on the local network — deliberately not opened for Open WebUI and n8n. Both services are nonetheless already published over HTTPS for external access, via the VM200 reverse proxy (see Reverse Proxy), which relays the request without exposing the internal port.
🔒 SSH hardening
bash
# /etc/ssh/sshd_config PermitRootLogin no PasswordAuthentication no PubkeyAuthentication yes MaxAuthTries 3 ClientAliveInterval 300 # Générer une clé SSH ssh-keygen -t ed25519 -C 'portfolio-ia' # Copier la clé ssh-copy-id -i ~/.ssh/id_ed25519.pub user@proxmox-host # Vérifier les règles firewall iptables -L -n -v