[SOLVED] Create and Setup vLan with Tag in PVE behind pfSense Firewall

Sep 29, 2023

I´m really having trouble setting up a vLAN in/on PVE and make it available to the firewall and give access to WAN.

pfSense Firewall with public IP and 2 physical interfaces (WAN and LAN)
WAN provides Internet
LAN Network (Intern IP:

An PVE Instance is connected to LAN with
vmbr0 - Gateway

On the PVE there are running 2 VMs which I want to separate via vLAN.

VM1: (connected via vmbr0)
VM2: (connected via vmbr0)

Now I want to separate those networks via vLAN.

What I already did:
I made vmbr0 vLan aware
Gave VM2 a tag: 20
Created a vLan in pfsense, assigned it to a new interface OPT1 and give a different IP range and created Firewall etc.
Assigned VM2 a new Address and Gateway

My Problem is that with VM2 (vLAN 20) I can't out of the system, can't even ping anything, pfsense or www.
I know I still missing some network configuration, I think some Bridge etc on PVE.

For better understanding I attached a image of the setup.

Could anyone please give me a hint, what is wrong?


  • overview.png
    546.2 KB · Views: 15
Last edited:


The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!