I am currently not using proxmox firewall. I have a single vlan aware bridge vmbr0 and all VMs/CTs use it along with a VLAN tag (or none, if they need access to all VLANs such as a virtual router).
If I were to enable the firewall, what would happen? What would happen to my bridge and where would the firewall be exactly inserted? Would it be ebtables rules or iptables rules? And in the latter case, how? It would need to different L2 networks...
The reason why I am asking and why I am so confused about it is that even if I add a new network interface to my VMs or CTs, it seems I can always only add bridged interfaces:


Lastly, I also note that I have some networks where I definitely need to preserve the addressing. For example, I have a public /28 which some VMs use. Is it still possible to use the proxmox firewall in those instances (e.g. via ebtables or some sort of NAT)?
If I were to enable the firewall, what would happen? What would happen to my bridge and where would the firewall be exactly inserted? Would it be ebtables rules or iptables rules? And in the latter case, how? It would need to different L2 networks...
The reason why I am asking and why I am so confused about it is that even if I add a new network interface to my VMs or CTs, it seems I can always only add bridged interfaces:


Lastly, I also note that I have some networks where I definitely need to preserve the addressing. For example, I have a public /28 which some VMs use. Is it still possible to use the proxmox firewall in those instances (e.g. via ebtables or some sort of NAT)?