Based on that information, your ISP would need to effectively be bridged to your endpoint (PPP or PPPeE) as you only have 1 IP address (or no IP address and 1 network adresss...) Anyway to my mind your have some funky Point to Point connection, which should in theory be bridged to a firewall/router where you would then have your Firewall/NAT and create a private 'RFC 1918' network for Proxmox, VMs etc.
I hope any of that made sense. There are plenty of discussions on the forums out there on /32, /31 and Double NATTED connections. ( Starlink being a noteable example). There are ways to mitigate the restricted nature of a double NAT or bridged WAN link , like CLoudfares Zero trust Tunnels which effectively bypass your firewall and ISP completely.
I'm not sure I understand the role of this VM as an edge device. Please provide more details on the physical connection you are attempting to to your service providers equipment. In other words, there needs to be a router/firewall which provides NAT to your private LAN