Adding Management Interface LAN side

foxhotel

New Member
Jul 4, 2024
3
0
1
Let's start with I am not good at this. This grew from 3d printing and cnc control and I'm at the edge of my nerdery but it's working.

That said -- I have up and working proxmox w/ opensense and a few computers sitting on a lan together all working well. its a passthrough ip from my ISP to the box, proxmox on it, opensense on it. vtnet0 is my wan, vtnet1 is my lan to a tplink smart switch. pretty simple. everything works. well.

however. i remote a lot. i use wireguard (which is working great -- i am on my entire lan when i'm gone -- perfect). however. i cannot get to my proxmox webui instance from my lan, it only has an ip on the "wan" side (the at&t network of the router they provide that the whole family is on). I have a native ethernet nic and 2xusb nic's. they all work fine. Right now i'm only using the native eth and one of the usb dongles (native is "in from the wan w/ ip passthrough" and the usb one feeds my lan).

is there a way to have proxmox UI access from the lan side? either exclusively or in conjunction w/ the wan access point? i can use this third usb nic if required? is this called management access when you guys talk about it?

attached is my interfaces file. my att lan is 192.168.1.x/24 and my lab lan is 192.168.2.x/22. i have all 3 nics bridged and passed to opensense but i don't "see" the third nic on the lab lan side in opensense (not sure why ... but when i try to fix it things break hard).

i'm really hoping for a simple answer. i have blown up my network three times now trying to do this (nope, not sure why, but i now know how to backup opensense like a boss). i'm not trying to make a universal network to take over the universe, i'm just trying to arrange my network to help my physical workflow in fabrication. thanks in advance, i've read a whole lot on here and w/o this forum I wouldn't have gotten this far!

1720064318145.png
 
Last edited:
PVE GUI listen on every iface with ip so you can use this (routing, nat, etc). Or you can use reverse proxy (frontend lan, backend "wan") etc.
 
i'm so close to understanding that. are you saying that if i hit https://192.168.2.135:8006 while on a machine in the homelan w/ an ip in that subnet that i should get the proxmox webui? that's what i'm taking from "PVE GUI listen on every interface", vmbr2 is an interface, it is on the lan from which i desire access, proxmox is listening on it?

because if i'm supposed to be able to see the webui from that ip then ... then i dunno. maybe i need an opensense rule to allow it? but opensense doesn't even see that nic (and it is in the subnet block). am i making this harder than it is?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!