Setting Up Proxmox Networking
What this article covers
- How networking is organized in Proxmox.
- What bridges, VLANs, and bonding are.
- How to plan IP addresses and subnets.
- How the built-in firewall works.
- Tips for accessing LXC, VMs, and the host itself.
Introduction: Setting up Proxmox networking
A well-designed network is the foundation of a stable Proxmox homelab. Proxmox uses Linux bridges to provide virtual network interfaces for VMs and containers. VLANs let you logically separate networks, and the built-in firewall enables fine-grained access control. Planning your network properly from the start prevents headaches with IP allocation, connectivity, and security later on.
This article explains the key networking concepts in Proxmox and shows how to build a solid setup.
Key terms
- Bridge: A virtual network switch that connects physical and virtual interfaces.
- vmbr0: The default bridge in Proxmox.
- VLAN: Virtual Local Area Network, for logical network segmentation.
- Bond: Combining multiple network ports for redundancy or increased bandwidth.
- Subnet: The address range of a network, for example
192.168.1.0/24. - Gateway: The exit point to another network, typically the internet.
- DNS: Resolution of hostnames to IP addresses.
- Firewall: Rules that permit or block network connections.
Standard setup
After installation, Proxmox typically has:
- vmbr0: Bound to the physical network interface.
- IP: Assigned manually or via DHCP.
- Gateway and DNS: For the host’s internet access.
VMs and LXC containers get their virtual network interface through this bridge and thus share the same network as the host.
Configuring bridges
In /etc/network/interfaces or via the GUI:
auto vmbr0
iface vmbr0 inet static
address 192.168.1.10/24
gateway 192.168.1.1
bridge-ports enp0s31f6
bridge-stp off
bridge-fd 0
bridge-ports specifies the physical interface attached to the bridge.
VLANs
VLANs let you separate networks across the same physical link. Proxmox supports two approaches:
VLAN on the bridge
iface enp0s31f6 inet manual
auto vmbr0.10
iface vmbr0.10 inet static
address 10.0.10.10/24
vlan-raw-device vmbr0
VLAN in the guest
In the guest interface config, you specify tag=10. The physical switch must trunk that same VLAN.
DHCP or static IPs
For servers and the Proxmox host itself, static IP assignment is recommended. For temporary test VMs, DHCP can work fine. Crucially, the Proxmox host’s IP should be fixed, otherwise you’ll lose web access.
Bonding
If multiple network ports are available, you can combine them into a bond:
auto bond0
iface bond0 inet manual
bond-slaves enp1s0 enp2s0
bond-miimon 100
bond-mode 802.3ad
auto vmbr0
iface vmbr0 inet static
address 192.168.1.10/24
gateway 192.168.1.1
bridge-ports bond0
The switch must support LACP.
Networking for LXC and VMs
When creating an LXC or VM, you attach a network card to a bridge. A typical configuration looks like:
net0: virtio,bridge=vmbr0,tag=20,ip=dhcp
For static IPs:
net0: virtio,bridge=vmbr0,ip=192.168.1.50/24,gw=192.168.1.1
Proxmox Firewall
Proxmox has a built-in firewall that can be enabled at the datacenter, VM, or LXC level:
- Enable it at the datacenter firewall level.
- Create a security group or per-VM/LXC rule.
- Define the direction:
INorOUT. - Allow or block specific ports and IP ranges.
Example: Allow SSH only from the local network.
Separating management and guest networks
For better security, separation is recommended:
- Management network: For Proxmox web interface, SSH, and IPMI.
- Guest network: For VMs and LXC.
- DMZ: For publicly accessible services.
- IoT/VLAN: For smart home devices or external connections.
DNS and name resolution
Proxmox uses /etc/resolv.conf or systemd-resolved. In VMs and LXC containers, use a local DNS server like Pi-hole, AdGuard Home, or your router so devices on the network can reach each other by hostname.
Tailscale and VPN
For remote access, you can run Tailscale on the Proxmox host or in a gateway LXC. This lets you reach your internal network without opening ports to the internet.
Common pitfalls
- Bridge misconfigured: No network access.
- VLAN tag missing: Guest ends up on the wrong network.
- IP conflicts: Duplicate addresses on the network.
- Firewall too restrictive: All traffic blocked without exceptions for management.
- Missing gateway or DNS: No internet access for guests.
- Wrong bridge on VM: VM is unreachable.
Further reading
- BotServ.de Proxmox basics
- BotServ.de Proxmox LXC vs. VM
- BotServ.de Proxmox storage
- BotServ.de Tailscale basics
FAQ: Proxmox networking
Can I have multiple bridges? Yes, for example one per VLAN or network segment.
Do I need VLANs? Not mandatory for small setups, but very helpful for security and organization.
How do I test network connectivity on an LXC?
Run ping 1.1.1.1 and ip a inside the container.
What is bonding? Combining multiple network ports for higher bandwidth or redundancy.
Should I use the Proxmox firewall? Yes, especially in larger setups or when services are exposed to the network.
Sources and further reading
- Proxmox Network Configuration: https://pve.proxmox.com/wiki/Network_Configuration
- Proxmox Firewall: https://pve.proxmox.com/wiki/Firewall
- Linux Bridge: https://wiki.linuxfoundation.org/networking/bridge
Summary: Setting up Proxmox networking
A solid Proxmox network design rests on clear bridges, sensible IP subnets, and optional VLANs for segmentation. The built-in firewall and tools like Tailscale add security on top. The key is to separate management from guest networks, assign static IPs to critical systems, and apply VLAN tags consistently. Planning your network from the start saves you from tedious troubleshooting later.


