What are the best practices for managing several subnets?

ZyX

New Member
Aug 15, 2023
15
2
3
France
Hello,

I would like to know what the recommendations are for managing subnets in a cluster of several proxmox nodes.

Let's imagine the following scenario:

I have 2 Proxmox nodes clustered in the network (192.168.100.0/24):
  • The IP of node 1 is 192.168.100.10
  • The IP of node 2 is 192.168.100.11

I have 2 vnets in the same SDN zone:
  • VNET1:
    • Subnet1: 10.1.1.0/24
    • Subnet2: 10.1.2.0/24
    • Subnet3: 10.1.3.0/24
  • VNET2:
    • Subnet1: 10.2.1.0/24
    • Subnet2: 10.2.2.0/24
    • Subnet3: 10.2.3.0/24

I have a firewall in a VM (pfSense for example) on one of the 2 nodes, I want to make sure that when I create a subnet in one of the vnet on Proxmox, it is automatically known by the pfSense (via BGP?) and that the default gateway for the VMs is the firewall.

I want to make sure that the flow between subnets is discarded by default and that I accept it if necessary on the firewall.

I'm thinking that an EVPN zone would be best but is that really the case?

Thanks in advance for your help
 
After a few tests, here's what I found:

I can create an EVPN zone, link the VNET interface to my pfSense and create the subnets directly on the pfSense: in this case, do I really need an EVPN zone? Wouldn't a VXLAN zone be enough?

If the VXLAN zone is sufficient, is it useful to activate the VLAN Aware option or is associating several networks on my pfSense interface "secure" enough?

In terms of scalability, will I run into performance problems using VXLAN if I start having a lot of VMs/CTs?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!