Open vSwitch vs. automatic tap interfaces


Dec 6, 2019

I'm using Open vSwitch on my proxmox box (proxmox 6.1-3, ovs version 2.10.1). I had hoped to mirror all traffic on one bridge to a guest machine's tap interface, which I would use as the monitoring interface for the security onion running within that vm. I found a few references to this technique online (e.g.

When this didn't work for me (tap interface "doesn't exist in table Port"), I eventually discovered that proxmox is creating the vm tap interfaces on linux bridges named fwxxx rather than in ovs. Is this the way it's supposed to work? Is there some way to configure proxmox so that all of the bridges and interfaces it creates are done so within ovs?

Alternately, can anyone suggest a better technique for mirroring all traffic on a virtual bridge to a network device in a vm?


Okay, I discovered that if a guest machine's network device has the firewall option enabled, then its tap interface will be created within a linux bridge. Unchecking the firewall box in the vm network device editor popup causes the tap interface to be created within the ovs bridge.


The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!