Sounds like you are using Basic zone (with possibly improper IP/network setup). Can you confirm/expain your networking/zone setup?
Best, On Fri, Sep 18, 2026 at 4:38 PM Drew Weaver <[email protected]> wrote: > Hello, > > Our one real requirement for the network operation for this project is > basic network filtering so that if for example someone just assigns the IP > address of the gateway for the VLAN's subnet to their VM's vNIC it doesn't > break everything. > > The problems we noticed with our original PoC: > > We were planning on using firewalld to protect the management IPs on the > hypervisors but we noticed that the only way we could get the guest VM > networking to function is to disable firewalld. > If we tried pinging an IP address that was assigned to a guest VM which is > on a completely different network entirely the management NIC IP would just > reply back with "filtered" until firewalld was disabled. > > We also noticed that the SystemVMs by default create a "defacto bridge" > between the public/guest network by having one NIC in each of these > networks. This is undesirable for us so I am trying to find an alternative. > > The questions are: > > Is it expected that having firewalld running would make it impossible to > route traffic to the guestVM network or did I just not find the right > kernel tuning/routing/firewalld setting to make it work? > > If you can use firewalld to protect the management NIC IP address does > that interfere with the basic network filtering I mentioned as a > requirement for this? > > Is there a way to put the "public" vNIC for the system VMs in another > VLAN/subnet other than the pool that the guest VMs use if so does anyone > know how to facilitate this? > > Our new PoC we are planning will use local storage on the HVs only and > there will be 2x1G NICs [bond0] and 2x10G NICs [bond1] > > Cloudbr0 [bond0] native VLAN will be the actual "management" network, and > then if it's possible the "public network for the System VMs" will be just > a trunked vlan to the bond. > Cloudbr1 [bond1] will just have the guest VM network trunked to the > guestVM network > > Does this seem like a workable configuration? > > Thanks for your time. > -Drew > > > > > > > > > > > > -- Andrija Panić
