marmot-te wrote on 1/8/19 3:55 PM:
You only need that to be an HVM if you're planning on assigning a
dedicated NIC to it. That would probably be the easiest fix, but you are
bypassing Qubes' networking security.
Otherwise, you're on the right track with the Qubes firewall document
you referenced. You could write rules so the source permits an entire
subnet, not just a single IP. Iptables/NFT rules aren't very
straight-forward though; afraid I can't help there.
In either case, test from a web browser inside the VM to make sure the
web server is working before testing from external.