]> git.proxmox.com Git - pve-docs.git/blame - pve-firewall-vm-opts.adoc
update link qemu documentation non web.archive
[pve-docs.git] / pve-firewall-vm-opts.adoc
CommitLineData
5c1699e5 1`dhcp`: `<boolean>` ('default =' `0`)::
78ef35dc
DM
2
3Enable DHCP.
4
5c1699e5 5`enable`: `<boolean>` ('default =' `0`)::
78ef35dc
DM
6
7Enable/disable firewall rules.
8
013dc89f 9`ipfilter`: `<boolean>` ::
78ef35dc 10
de0983cb 11Enable default IP filters. This is equivalent to adding an empty ipfilter-net<id> ipset for every interface. Such ipsets implicitly contain sane default restrictions such as restricting IPv6 link local addresses to the one derived from the interface's MAC address. For containers the configured IP addresses will be implicitly added.
78ef35dc 12
013dc89f 13`log_level_in`: `<alert | crit | debug | emerg | err | info | nolog | notice | warning>` ::
78ef35dc
DM
14
15Log level for incoming traffic.
16
013dc89f 17`log_level_out`: `<alert | crit | debug | emerg | err | info | nolog | notice | warning>` ::
78ef35dc
DM
18
19Log level for outgoing traffic.
20
5c1699e5 21`macfilter`: `<boolean>` ('default =' `0`)::
78ef35dc
DM
22
23Enable/disable MAC address filter.
24
5c1699e5 25`ndp`: `<boolean>` ('default =' `0`)::
78ef35dc 26
5c1699e5 27Enable NDP (Neighbor Discovery Protocol).
78ef35dc 28
013dc89f 29`policy_in`: `<ACCEPT | DROP | REJECT>` ::
78ef35dc
DM
30
31Input policy.
32
013dc89f 33`policy_out`: `<ACCEPT | DROP | REJECT>` ::
78ef35dc
DM
34
35Output policy.
36
013dc89f 37`radv`: `<boolean>` ::
78ef35dc
DM
38
39Allow sending Router Advertisement.
40