Hello everyone!
I'm not proficient in networking, and after two days of testing, I decided to ask here if what I'm doing is correct or not.
Let's start from the beginning: I just bought a Kimsufi server from OVH. A very good deal. Like every Kimsufi server, you cannot have more than one public IP. But for what I planned to do, it's enough. I installed Proxmox 8 on it, created a VM with OPNsense, and created two bridges like this:
data:image/s3,"s3://crabby-images/ef0e3/ef0e389091e8b0fda73940787b96e653d98b90e4" alt="1718191674124.png 1718191674124.png"
Under the red lines, for the vmbr0 bridge, we configured the IPv4 and gateway with the same values as my server interface, retrieved from the OVH dashboard:
data:image/s3,"s3://crabby-images/b51e1/b51e193637d8c3445eb12c1e5a45ae0d4cac1222" alt="1718191491098.png 1718191491098.png"
As you can imagine, this is my WAN. For the LAN, I created another bridge without a NIC. Here is a diagram of what I have in mind:
data:image/s3,"s3://crabby-images/c068f/c068f22f9ecc4f13f8a9a53de4e7418871328eca" alt="diagram.drawio.png diagram.drawio.png"
Right now, I'm stuck at the first step. OPNsense seems unable to reach the router. If I try to ping it, I get no response.
So I have two questions at the moment:
I'm not proficient in networking, and after two days of testing, I decided to ask here if what I'm doing is correct or not.
Let's start from the beginning: I just bought a Kimsufi server from OVH. A very good deal. Like every Kimsufi server, you cannot have more than one public IP. But for what I planned to do, it's enough. I installed Proxmox 8 on it, created a VM with OPNsense, and created two bridges like this:
data:image/s3,"s3://crabby-images/ef0e3/ef0e389091e8b0fda73940787b96e653d98b90e4" alt="1718191674124.png 1718191674124.png"
Under the red lines, for the vmbr0 bridge, we configured the IPv4 and gateway with the same values as my server interface, retrieved from the OVH dashboard:
data:image/s3,"s3://crabby-images/b51e1/b51e193637d8c3445eb12c1e5a45ae0d4cac1222" alt="1718191491098.png 1718191491098.png"
As you can imagine, this is my WAN. For the LAN, I created another bridge without a NIC. Here is a diagram of what I have in mind:
data:image/s3,"s3://crabby-images/c068f/c068f22f9ecc4f13f8a9a53de4e7418871328eca" alt="diagram.drawio.png diagram.drawio.png"
Right now, I'm stuck at the first step. OPNsense seems unable to reach the router. If I try to ping it, I get no response.
So I have two questions at the moment:
- Is the architecture I planned actually valid?
- Why does bridging the NIC and attaching it to a VM not expose it to the internet?