Using OPNSense in a VM as FW/router on single-NIC host

FlyveHest

New Member
Sep 17, 2025
5
0
1
Denmark
I'm gearing up to installing my first ProxMox server, but I just found out that its very possible that I will only be able to get a single IP for the host at my hosting provider.

So, i've been thinking about how to setup the server, and i'm wondering if a scenario like the following is possible?

Running OPNSense in a VM and assigning the single public IP to that host, and then using that for NATing and WireGuard connections to connect to VMs / CTs running on the host.

The main reason i'm asking is that it looks like setting up a bridge "consumes" an IP, and as i've only got the one, there won't be one available for the OPNSense VM.

Do I have to assign an IP to the "WAN" bridge? Or can I setup a bridge with no IP and assign the one public ip to a VM connected to that bridge? (Which will be the only thing connected to that bridge)