1
General Discussion / Proxmox OPNSense configuration
« on: March 31, 2017, 03:11:52 am »
Hello everybody.
After switching to OPNSense on my home network, i want to give it a try on a dedicated Proxmox node.
Currently im running a serval kvm based VM's on my server wich are available via static ip on the internet, getting their ip from my proxmox dhcp server.
I want to use OPNSense firewall and DHCP server without NAT, since i want all my VMs to be available via their own IP.
Running the proxmox dhcp server on vmbr0 wich is bridged to eth0, i created a second bridge (vmbr1) wich i want to assign to the "LAN" side of OPNSense.
I got a /29 IPv4 subnet (5 IPs), one IP used for the proxmox node, 3 for VMs and one unused.
Do i need a WAN IP for OPNSense?
Can i configure OPNSense to be available for the VMs without "wasting" one of my IP's?
Any tipps for my configuration?
Im a bit stuck here, this is the first time im trying to setup something like this.
Added a illustration to show what i want...
Thanks in advance for any helpful info!
Tanks for this wonderful piece of software
After switching to OPNSense on my home network, i want to give it a try on a dedicated Proxmox node.
Currently im running a serval kvm based VM's on my server wich are available via static ip on the internet, getting their ip from my proxmox dhcp server.
I want to use OPNSense firewall and DHCP server without NAT, since i want all my VMs to be available via their own IP.
Running the proxmox dhcp server on vmbr0 wich is bridged to eth0, i created a second bridge (vmbr1) wich i want to assign to the "LAN" side of OPNSense.
I got a /29 IPv4 subnet (5 IPs), one IP used for the proxmox node, 3 for VMs and one unused.
Do i need a WAN IP for OPNSense?
Can i configure OPNSense to be available for the VMs without "wasting" one of my IP's?
Any tipps for my configuration?
Im a bit stuck here, this is the first time im trying to setup something like this.
Added a illustration to show what i want...
Thanks in advance for any helpful info!
Tanks for this wonderful piece of software