Hardware & Advanced Topics

How can we help?

Guides and technical documentation for your Server4You dedicated server or VPS.

Proxmox VE: Additional IPs for VMs and Containers

On a dedicated server with Proxmox VE, you assign additional public IPs to VMs and containers via an internal bridge and 1:1 NAT on the host. This is needed because only the MAC address of the server itself is allowed on the network.

Note: Advanced virtualization networking is not covered by the standard Support Scope and requires technical experience.

View Support Scope →

The Concept: Why NAT?

Our network only accepts traffic from the physical MAC address of your server. VMs and containers have their own virtual MAC addresses, so they would be blocked if you attached them directly to the public bridge vmbr0.



The solution: The Proxmox VE host acts as a gateway. Your guests sit on an internal bridge (e.g. vmbr1) with a private subnet. The host accepts traffic for your additional public IPs on vmbr0 and forwards it to the matching guest (1:1 NAT), so only the authorized MAC address of the server is visible to the outside.



If you have not set up Proxmox VE yet, start with First Steps with Proxmox VE.

1

Create an Internal Bridge

On a Server4You Proxmox VE installation, vmbr0 carries the public main IP of the host and is attached to the physical network card. Check the names of your interfaces first:

Check Interfaces
ip a

Create a second bridge without a physical port. In the web interface, select your node and go to System → Network → Create → Linux Bridge: name vmbr1, IPv4/CIDR 10.10.10.1/24, no gateway, leave Bridge ports empty. Alternatively, add the following block to /etc/network/interfaces:

/etc/network/interfaces (excerpt)
auto vmbr1 iface vmbr1 inet static address 10.10.10.1/24 bridge-ports none bridge-stp off bridge-fd 0

Do not change the existing vmbr0 block. A faulty configuration on vmbr0 can make the server unreachable; in that case, start the rescue mode in the PowerPanel and correct the file from there.

2

Enable IP Forwarding Permanently

Allow the kernel to pass traffic between vmbr0 and vmbr1. The file in /etc/sysctl.d/ keeps the setting after a reboot:

Enable IP Forwarding
echo "net.ipv4.ip_forward = 1" > /etc/sysctl.d/99-ip-forward.conf sysctl --system
3

Set Up 1:1 NAT Rules

The host must answer for the additional IP, so add it to vmbr0 as well (see Configure an Additional IP Address). The Proxmox-typical way to make NAT rules persistent is post-up and post-down lines in /etc/network/interfaces. Add them to the vmbr1 block; replace 203.0.113.11 with your additional IP and 10.10.10.11 with the private IP of the guest:

/etc/network/interfaces (vmbr1 with 1:1 NAT)
auto vmbr1 iface vmbr1 inet static address 10.10.10.1/24 bridge-ports none bridge-stp off bridge-fd 0 # Additional IP 203.0.113.11 on the public bridge post-up ip addr add 203.0.113.11/32 dev vmbr0 post-down ip addr del 203.0.113.11/32 dev vmbr0 # Incoming: public IP to guest post-up iptables -t nat -A PREROUTING -i vmbr0 -d 203.0.113.11 -j DNAT --to-destination 10.10.10.11 post-down iptables -t nat -D PREROUTING -i vmbr0 -d 203.0.113.11 -j DNAT --to-destination 10.10.10.11 # Outgoing: guest leaves with its public IP post-up iptables -t nat -A POSTROUTING -s 10.10.10.11 -o vmbr0 -j SNAT --to-source 203.0.113.11 post-down iptables -t nat -D POSTROUTING -s 10.10.10.11 -o vmbr0 -j SNAT --to-source 203.0.113.11

Repeat the three line pairs for each additional IP and guest. Then apply the configuration without a reboot:

Apply Configuration
ifreload -a iptables -t nat -L -n -v

If you use the Proxmox VE firewall for guests, also add post-up iptables -t raw -I PREROUTING -i fwbr+ -j CT --zone 1 and the matching post-down line with -D, as described in the Proxmox documentation. Otherwise, connection tracking for NAT can fail.

Alternative: In a routed setup, the guests get the public IPs directly on vmbr1, and the host routes them via vmbr0 (with proxy_arp). This avoids NAT but requires that your additional IPs are routed to the main IP of the server. Details are in the Proxmox documentation linked below.

4

Inside the VM or Container

Network Device

VM: Hardware → Network Device, container: Network → net0. Set the bridge to vmbr1. Inside the guest (or directly in the container settings), configure the private IP with the bridge IP as gateway.

Example Guest Config:
Bridge: vmbr1
IP: 10.10.10.11/24
Gateway: 10.10.10.1
DNS: 1.1.1.1

External Resources & Troubleshooting

Since this configuration is outside our support scope, we recommend consulting official documentation and community resources for in-depth troubleshooting and advanced network scenarios.