Proxmox Mac Filter & NAT


Jun 23, 2022
Hello Everyone,

i stumbled across an issue with Mac filter and hoping someone will be able to advise if there is a workaround.
Also searched the web and forums with no luck

I have firewall and mac filter enabled for datacenter and vm's

VM-1 has 2 ip addresses, one public and one private, VM-2 has only private ip addresses.
Nating from VM-1 ( port forwarding ) to VM-2 does not work when mac filter on VM level is enabled.
Outbound nat from VM-2 through VM-1 does work when mac filter on VM level is enabled.
Both VM's can ping each other internally.

Is there any workaround to fix the inbound nat from VM-1 to VM-2 while keeping the Mac Address filtering enabled to prevent spoofing?

I forgot to mention that i have IPSET enabled on each VM interface.


Disabling mac filter and ip filter on VM-1 does not allow inbound nat to work, i have to disabling the firewall itself under this VM for it to work
This confuses things i guess?!

Firewall Inbound policy is set to ALLOW


The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!