Based on that information, your ISP would need to effectively be bridged to your endpoint (PPP or PPPeE) as you only have 1 IP address (or no IP address and 1 network adresss...) Anyway to my mind your have some funky Point to Point connection, which should in theory be bridged to a firewall/router where you would then have your Firewall/NAT and create a private 'RFC 1918' network for Proxmox, VMs etc.
I hope any of that made sense. There are plenty of discussions on the forums out there on /32, /31 and Double NATTED connections. ( Starlink being a noteable example). There are ways to mitigate the restricted nature of a double NAT or bridged WAN link , like CLoudfares Zero trust Tunnels which effectively bypass your firewall and ISP completely.
:Edited for clarity (Its late here)