Help Configuring second bridge on different subnet

atsumori

New Member
Nov 4, 2024
2
0
1
Hi, I'm new to Proxmox and hoping someone can help me with a setup question. I have proxmox connected to my ISP router, and then within that proxmox OPNsense running in a VM within proxmox that handles the firewall and everything for my internal network. I am trying to setup an LXC on the internal network side through the same proxmox machine but I cannot get the lxc to connect to OPNsense so I was wondering if someone could look through my settings to see if I'm missing something.

Some notes
  1. All of OPNsense's interfaces are passed through with IOMMU or SR-IOV so not shared with the proxmox host.
  2. I have two linux bridges (vmbr0 and vmbr1). Both have assigned IP addresses in proxmox (one on internal network, one on ISP router side) and they both are verified connected to the network as I can access the proxmox webui from either address
  3. I am creating the LXC with the proxmox helper scripts for unifi network from here. When I assign it the vmbr0 I can create the lxc without problem except its on the wrong side of my network. When I create it with vmbr1 I can create the lxc but it can't access the network (and it doesn't matter if I use dhcp or statically assign the IP when creating the LXC)
  4. It doesn't appear to be a firewall problem as I'm not seeing anything arriving in OPNSense at all (blocked or not).

network setup

ISP router (192.168.3.1)
|
|
Proxmox (192.168.3.2)
---->OPNSense (192.168.3.100 <--> 192.168.1.2)
|
|
Switch + 192.168.1.1 subnet

Relevent Network Setup in Proxmox

enp88s0: Autostart
enp3s0f0v7: Autostart

vmbr0: Autostart
VLAN Aware​
Bridge=enp88s0​
IPv4/CIDR: 192.168.3.2/24​
Gateway: 192.168.3.1 (ISP router)​
vmbr1: Autostart
VLAN Aware​
Bridge=enp3s0f0v7​
IPv4/CIDR: 192.168.1.60/24​
 
Last edited:
shutdown opnsense.
destroy vmbr1
rebuild , after applied configuration, your vmbr1. Unload vlan aware if you don't use it explicitly in your CT
 
Thanks! I tried shutting down opnsense, destroying and rebuilding vmbr1 without vlan aware, and then rebuilding the container but I'm still not connecting to the network from within the container.
 
i only know the pfsense alternative. Did you have good declared your default gateway for your internal network ?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!