Proxmox VE: Additional IPs for VMs and Containers
On a dedicated server with Proxmox VE, you assign additional public IPs to VMs and containers via an internal bridge and 1:1 NAT on the host. This is needed because only the MAC address of the server itself is allowed on the network.
Note: Advanced virtualization networking is not covered by the standard Support Scope and requires technical experience.
View Support Scope →
The Concept: Why NAT?
Our network only accepts traffic from the physical MAC address of your server. VMs and containers have their own virtual MAC addresses, so they would be blocked if you attached them directly to the public bridge vmbr0.
The solution: The Proxmox VE host acts as a gateway. Your guests sit on an internal bridge (e.g. vmbr1) with a private subnet. The host accepts traffic for your additional public IPs on vmbr0 and forwards it to the matching guest (1:1 NAT), so only the authorized MAC address of the server is visible to the outside.
If you have not set up Proxmox VE yet, start with First Steps with Proxmox VE.
Create an Internal Bridge
On a Server4You Proxmox VE installation, vmbr0 carries the public main IP of the host and is attached to the physical network card. Check the names of your interfaces first:
Create a second bridge without a physical port. In the web interface, select your node and go to System → Network → Create → Linux Bridge: name vmbr1, IPv4/CIDR 10.10.10.1/24, no gateway, leave Bridge ports empty. Alternatively, add the following block to /etc/network/interfaces:
Do not change the existing vmbr0 block. A faulty configuration on vmbr0 can make the server unreachable; in that case, start the rescue mode in the PowerPanel and correct the file from there.
Enable IP Forwarding Permanently
Allow the kernel to pass traffic between vmbr0 and vmbr1. The file in /etc/sysctl.d/ keeps the setting after a reboot:
Set Up 1:1 NAT Rules
The host must answer for the additional IP, so add it to vmbr0 as well (see Configure an Additional IP Address). The Proxmox-typical way to make NAT rules persistent is post-up and post-down lines in /etc/network/interfaces. Add them to the vmbr1 block; replace 203.0.113.11 with your additional IP and 10.10.10.11 with the private IP of the guest:
Repeat the three line pairs for each additional IP and guest. Then apply the configuration without a reboot:
If you use the Proxmox VE firewall for guests, also add post-up iptables -t raw -I PREROUTING -i fwbr+ -j CT --zone 1 and the matching post-down line with -D, as described in the Proxmox documentation. Otherwise, connection tracking for NAT can fail.
Alternative: In a routed setup, the guests get the public IPs directly on vmbr1, and the host routes them via vmbr0 (with proxy_arp). This avoids NAT but requires that your additional IPs are routed to the main IP of the server. Details are in the Proxmox documentation linked below.
Inside the VM or Container
Network Device
VM: Hardware → Network Device, container: Network → net0. Set the bridge to vmbr1. Inside the guest (or directly in the container settings), configure the private IP with the bridge IP as gateway.
Example Guest Config:
Bridge: vmbr1
IP: 10.10.10.11/24
Gateway: 10.10.10.1
DNS: 1.1.1.1
External Resources & Troubleshooting
Since this configuration is outside our support scope, we recommend consulting official documentation and community resources for in-depth troubleshooting and advanced network scenarios.