nat on VM work fine unless you enable the firewall

Ricardo Bernao

Active Member
Jan 4, 2018
I guys.

Before starting, i want to say that i have several experience on firewalls, networking and Proxmox.

I use make nat and firewalling on Proxmox VM using shorewall (iptables), but on a new proyect i decide to use proxmox firewall. My scenario is:

VMBR0 - Public IP with internet access
VMBR2 - LAN bridge.

Debian interface file content:

auto vmbr0
iface vmbr0 inet static
address MYpublicIP
netmask 24
gateway MYProviderGW
bridge-ports eno1
bridge-stp off
bridge-fd 0

auto vmbr2
iface vmbr2 inet static
netmask 24
bridge-ports none
bridge-stp off
bridge-fd 0
post-up echo 1 > /proc/sys/net/ipv4/ip_forward (although I enable this on sysctl.conf)
post-up /sbin/iptables -A POSTROUTING -t nat -o vmbr0 -s '' -j MASQUERADE
post-down /sbin/iptables -D POSTROUTING -t nat -o vmbr0 -s '' -j MASQUERADE

Proxmox 5.4.6 on debian 9
Up to this point, my VM on vmbr2 bridge with ip has internet conectivity without problem, so that nat works fine.

The problem comes when I enable cluster firewall. When I enable it, without rules, nat stop working.

I dont have another confgi or rules on iptables. what happen ?
Last edited:


The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!