pfSense on Proxmox installation and configuration - Step-by-step

แชร์
ฝัง
  • เผยแพร่เมื่อ 1 ธ.ค. 2024

ความคิดเห็น • 80

  • @steevem4990
    @steevem4990 ปีที่แล้ว +4

    just started this whole proxmox journey. my setup was a little different, i had a network card laying around that i added to my proxmox so i assigned 2 seperate port to pfsense. since i didnt have my lan network configured properly i had to desactivate packet filter entirely from wan port temporary and configure it from the ip my modem asigned it. once everything configured as i wanted i shifted the DHCP server from my tp-link router to my pfsense. after that i switched my tp-link router to an AP. really fun project and this video helped me a lot to make sur i started on good base.

  • @TracksWithDax
    @TracksWithDax ปีที่แล้ว +4

    I'm SUUUPER new, so this was helpful (but also took a lot of fiddling and watching other tutorials to wrap my head around).
    My PC has one ethernet port so I'm trying to make the best of that-
    What I ended up doing was making a second bridge not associated to any hardware, and having that be the primary NIC for my VMs.
    Put them all on the same subnet, gave pfSense a NIC that's on the same subnet as well as the LAN side and then a virtIO NIC for the WAN side - same interface as my main bridge which is associated with my physical ethernet port.
    I can access the web portal, but looks like a lot of fiddling to go before these VMs can connect to the internet through pfSense.

  • @johnvanwinkle4351
    @johnvanwinkle4351 10 หลายเดือนก่อน +1

    I am thinking about virtualizing my PFsense setup I have been using for years to consolidate the number of hardware machines running in my home server room. Thanks for a great walk thru about how to do this.

    • @VirtualizationHowto
      @VirtualizationHowto  10 หลายเดือนก่อน

      @johnvanwinkle4351 thank you for the comment! Be sure to join the forums to ask any questions or work through anything there: www.virtualizationhowto.com/community

  • @8bitkid408
    @8bitkid408 2 หลายเดือนก่อน

    Thank you for the video. The other videos by YT contributors on the subject are somewhat confusing. You explain it clearly and after some hurdles (USB NICs) I had my 5G router on one subnet and my LAN bridged on another subnet. All nice and safe. I have subscribed and look forward to binge watching your other content. Thank you very much. You are very much appreciated.

  • @DigiDoc101
    @DigiDoc101 ปีที่แล้ว +8

    How do you make sure your home network does not go out when you make changes to your host? Do you keep a pve machine for the fw alone?

  • @Maik.iptoux
    @Maik.iptoux ปีที่แล้ว +7

    Why no one had an video that shows the configuration when you DON'T have an router before pfsense? What is to do when the pfsense should be the only router so the WAN cable from modem is directly connected to proxmox host?

    • @mr.alkenly889
      @mr.alkenly889 ปีที่แล้ว

      Literally my same problem rn

    • @Maik.iptoux
      @Maik.iptoux ปีที่แล้ว

      ​@@mr.alkenly889Try to explain, I will try to help out

    • @RoryEckel
      @RoryEckel 11 หลายเดือนก่อน

      @@Maik.iptoux there is no proxmox web ui to log into without the network already running inside proxmox

  • @TheVictoire22
    @TheVictoire22 ปีที่แล้ว +3

    thx for the video. I was wondering. When you create pfsense as your firewall connecting the internet how will you update the Proxmox hypervisor? If you update it it doesn't have an internet connection anymore because the pfsense VM will go down I guess.

  • @joshsinykin5230
    @joshsinykin5230 ปีที่แล้ว +6

    how do you access the promox web mgmt gui from inside the pfsense lan side of the network?

    • @dominick253
      @dominick253 ปีที่แล้ว +1

      That's always been something I wondered about with vlans or multiple router systems. I would guess you'd have to have a port forwarding rule? To allow that port through from one vlan to another.

    • @EB-im8fu
      @EB-im8fu 2 หลายเดือนก่อน

      Simple, setup proxmox first, assigning it a static IP at Port 1 which by default becomes vmbr0. And use that same interface as the LAN interface of the pfsense VM. Just make sure the IP scheme of the proxmox server falls within the range of the IP scheme of your pfsense's LAN interface.

  • @vytautasbenetis8098
    @vytautasbenetis8098 10 หลายเดือนก่อน

    Thanks i had issues setting up the ip adresses but after watching your Video after the second installation everything worked fine and i found my mistake

  • @yuri.andopov.151
    @yuri.andopov.151 3 หลายเดือนก่อน

    What do you think, what is the argument for or against the other aproach when in pve you share a dedicated pcie network card directly to the pfSense as WAN, and use the default pve gateway as lan? No WAN traffic reaches the hosts kernel.

  • @ProperMethodz
    @ProperMethodz 7 หลายเดือนก่อน

    I wish you showed the creation of the bridge. I'm having an issue on this part where pfsense keeps telling me it doesn't exist after I create it.

  • @edditeyib
    @edditeyib ปีที่แล้ว

    dude that intro got me pumped

  • @pogiest1
    @pogiest1 2 ปีที่แล้ว +8

    I am specifically looking for a training that sets up Proxmox with the intent of using it for OPNsense or pfSense. Every training I see starts with Proxmox already configured. For me I need to know how to configure Proxmox so that it has disks to upload my ISO files. I want to know how to setup Proxmox networking configuration to use with OPNsense . So it would be nice to have a tutorial that starts with a clean appliance that is ready to install Proxmox and OPNsense on. I know there are networking considerations to keep in mind and disk partioning, but I don't see any tutorials for how to configure Proxmox specifically to use it to host a firewall.

    • @yvesgonzaga4223
      @yvesgonzaga4223 ปีที่แล้ว

      Check out this channel www.youtube.com/@TechnoTim

    • @brunospfc8511
      @brunospfc8511 ปีที่แล้ว

      yes, thank your, same problem here

  • @Suriprofz
    @Suriprofz ปีที่แล้ว +3

    Something i don't understand is that vmbr0 is used as WAN in pfsense VM. So thats the bridge to the interface where you will put the ISP cable in.
    And the LAN => where you put your switches etc.
    But the other VM's use vmbr0 i guess as default. so they would use the WAN port. which is just the ISP interface. no DHCP server or what so ever. should they use the lan port so vmbr1 then? to get ip etc and be available to access by LAN

    • @timezonewall
      @timezonewall ปีที่แล้ว

      The way he showed this was a little confusing, and not likely how one would set this up for production. Most people use PCI pass through for the WAN and LAN network interfaces (NICs), and the vmbr0 for the Proxmox would be on associated with a third NIC, separate from the LAN and WAN. It's more performant and secure to have WAN and LAN NICs passed through to pfsense.

    • @renalshomlmes338
      @renalshomlmes338 10 หลายเดือนก่อน

      ​@@timezonewallare you saying to have 3 separate cards, not just ports?

    • @timezonewall
      @timezonewall 10 หลายเดือนก่อน

      @@renalshomlmes338 It could be either one. More than likely, it would be one card passed through PCIe. I've used intel i340 based cards which typically have 4 ports. I use PCIe pass through for the entire card, then use one port for WAN, and three for LAN. For the NIC on the motherboard, I use that for management of Proxmox itself so it can be still accessed even if pfsense is down for maint or reboot. This would be a typical configuration for a lot of people.

    • @aleshen
      @aleshen หลายเดือนก่อน

      @@timezonewall hey, which network did you use for other VMs? If you passthrough NIC card to the pfSense then other proxmox VMs can't use any of the ports on it and motherboard's NIC is used for management. So the only option is to combine management network with other VMs right? Or am I missing something?

    • @timezonewall
      @timezonewall หลายเดือนก่อน

      @@aleshen One can use the motherboard NIC for both management and other VMs, or one can pass through individual NIC ports instead of passing the entire card. So if one has a 4 port card, and a MB NIC, they could use the MB NIC for management, 3 card ports for pfsense, and one card port for VMs. One can set it up for whatever works best for them

  • @ripaire
    @ripaire 2 ปีที่แล้ว +2

    Hi sir thanks for this amazing vidéo, but please make sure to make a vidéo about how to setup proxmox and configure it to use wifi adapter to be able to connect to wifi because there's no vidéo explain this point all people they use cable to connect there proxmox server please make a vidéo about wifi configuration. Thanks again

  • @Elijahcgts
    @Elijahcgts 3 หลายเดือนก่อน

    What if I use the single Ethernet port on my pc for the WAN and use the 8 other 1G Ethernet ports that I have among 2x NICS on the same machine as my LAN. Do I have to assign all 8 of those interfaces for LAN?

  • @HanedanKomutan
    @HanedanKomutan ปีที่แล้ว

    Hello, Proxmox And there is 1 pfsense and 1 windows 10 system inside, windows 10 pfsense is behind the lan port. Previously, I was accessing the proxmox web gui interface from Windows 10 with this structure. I forgot to take notes, I don't remember how to adjust it again. What should I do about this issue?

  • @AESJoe
    @AESJoe ปีที่แล้ว +1

    Can you make a video about proxmox errors and how to fix? I keep getting an QEMU error and can't find a fix....

    • @lindsaykid9947
      @lindsaykid9947 ปีที่แล้ว

      Yes I'm with you. It's frustrating as hell.

  • @CareyGButler
    @CareyGButler 5 หลายเดือนก่อน

    Add these two rules to your interfaces file and it will work correctly!
    post-up iptables -t raw -I PREROUTING -i fwbr+ -j CT --zone 1
    post-down iptables -t raw -D PREROUTING -i fwbr+ -j CT --zone 1

  • @davidkamaunu7887
    @davidkamaunu7887 ปีที่แล้ว +1

    I like your presentation it is smooth and easy to follow. Often it is the delivery of technical content to the audience that requires an easy to follow demonstrator. Thanks for this as I am setting up my own homelab right now. How many cores on your Proxmox VE node? I have a Quad core Phenom II X4 with 24Gb DDR3 I want to use and Im unsure of using it in this manner..

  • @brunospfc8511
    @brunospfc8511 ปีที่แล้ว +13

    You jumped the creation of the Virtual Network, "Step-by-setp" FAILED..

  • @vesa-matti86
    @vesa-matti86 9 หลายเดือนก่อน

    I now have a bare metal server on Hetzner with one IP4 address. How do I do this installation on it?

  • @jeffharwood624
    @jeffharwood624 ปีที่แล้ว

    Soooo....we de-compiled Proxmox, and re-scripted it now it works fine. ANY browser can now use it. We can install it in ubuntu with a wrapper. One and done.

    • @VirtualizationHowto
      @VirtualizationHowto  11 หลายเดือนก่อน

      @jeffharwood624, thanks for the comment! Sign up on the forums and I would love to have you share this in more detail: www.virtualizationhowto.com/community

  • @zyghom
    @zyghom ปีที่แล้ว

    so I have 3 LAN cards in my proxmox, all are connected to the switch, where also cable from the router comes. I understood it is a router (provided by ISP) that deals with IP on the WAN side but here you are saying something different. I am not sure how to connect all these things?
    Should the cable from the router come directly to the LAN card assigned as WAN on pfsense? and the other cards to the switch?
    or both: WAN and LAN cards can be connected to the same switch, where the cable from the route comes?
    can WAN and LAN be in the same segment (192.168.1.x)?

  • @Alex-un5tl
    @Alex-un5tl ปีที่แล้ว

    the only problem that virtualised pfsense that it is still connected to you physical upstream firewall, is there a way to directly connect your isp modem to WAN interface of your pfsense?

    • @VirtualizationHowto
      @VirtualizationHowto  ปีที่แล้ว +1

      Alex, thanks for the comment! Yes this is possible. You would need to create a VLAN interface that trunks out to your physical switch. You would then place your ISP modem to this same VLAN. It would then grab an IP and be configured the same as running a cable from the ISP modem directly into a pfsense appliance. Does this help?

  • @YannMetalhead
    @YannMetalhead 6 หลายเดือนก่อน

    Good video!

  • @RealKeytones
    @RealKeytones ปีที่แล้ว

    Do I have to install this on the first device after the router and then connect all devices through that or no?

  • @giancarlosrm
    @giancarlosrm ปีที่แล้ว

    Great content!! Let me ask you, Do you prefer Proxmox or Bare metal installation for a pfsense firewall? if you have vpn and encryption proxmox is giving me performance issues?

  • @zedtrek
    @zedtrek ปีที่แล้ว

    Hello, I just put the new virtualized PFsense online, all good but the connectivity seems to be quite slow. It should be around 500m/s but I'm getting 100, any idea where I should look at?

    • @VirtualizationHowto
      @VirtualizationHowto  ปีที่แล้ว

      Reno, do you know what type of virtual network adapter you are using? It sounds like it may not be the VirtIO driver?

    • @zedtrek
      @zedtrek ปีที่แล้ว

      @@VirtualizationHowto Hi mate, thanks for your reply. I'm always using the virtio, turns out it was the speed set to 100m, the auto-sense seems to be a bit strange in my device. I can reach 350 now, not bad but also not what I should see, I will keep monitoring, I'm not super confident this setup is the best though. To be precise, what I think would be better, is using the ethernet port in passthrough, at least the WAN port, I'm a bit worried about having "unfiltered" traffic entering the PVE. The issue is that in my configuration (125c (rev 04)) it didn't work. Did you ever try on yours?

    • @mrmoo1480
      @mrmoo1480 ปีที่แล้ว

      @@zedtrek Having the same issue. Limited to just shy of 100Mb of gigabit connection. How do you change the speed set? I have one VM with E1000 and another with Virtio. Currently running E1000 VM and seeing the 100Mb limit

    • @timezonewall
      @timezonewall ปีที่แล้ว

      @@zedtrek right, most people virtualizing pfsense or opnsense will pass through the NICs, it's more secure and more performant. The video should have covered that IMO, or at least discussed it.

    • @zedtrek
      @zedtrek ปีที่แล้ว

      @@timezonewall Hi mate, my comment was quite old, after that (and lot of digging, experiments) I end up reinstalling everything using the NIC in passtrough. It's perfect now, the minipc I'm using it's great, I'm running some.other VMs too on it.

  • @michaelcooper5490
    @michaelcooper5490 2 ปีที่แล้ว +1

    Hello Brandon, Do you do any consulting at all? This is a good Video but I am having difficulties getting it up and running.

    • @cournal09
      @cournal09 ปีที่แล้ว

      same here the image is not booting.

    • @michaelcooper5490
      @michaelcooper5490 ปีที่แล้ว

      @@cournal09 Let me know if you need some help....I would be happy to try and get it running for ya.

    • @cournal09
      @cournal09 ปีที่แล้ว

      @@michaelcooper5490 yesterday i got it working, after hours of reading. thanks for responding tho.😁

    • @robertmathers7852
      @robertmathers7852 ปีที่แล้ว

      @@cournal09 Are you trying to load the .gz file? You have to convert to .iso

  • @zippytechnologies
    @zippytechnologies 2 ปีที่แล้ว

    now, tell me about bond vs ovs bond without smart switch... so bonding extra nic's on each proxmox host for server to server and then fix up the isp provided public ip range (5 ip's) on one port from the ISP gateway... ugh not sure where to start... ddwrt was my friend for so long but now I need to grow...

  • @TJCooney
    @TJCooney 10 หลายเดือนก่อน

    i guess they updated this process because once installed the steps are now completely different.

  • @ronm6585
    @ronm6585 ปีที่แล้ว

    Thanks.

  • @SteveStowell
    @SteveStowell 2 ปีที่แล้ว

    Why e1000 network as your putting a demand on cou and vitriol works just fine

    • @VirtualizationHowto
      @VirtualizationHowto  2 ปีที่แล้ว

      This is a nested environment in ESXi where e1000 is a sure bet for compatibility. However, I assume VirtIO would work equally well.

    • @demanuDJ
      @demanuDJ 2 ปีที่แล้ว

      @@VirtualizationHowto VirtIO works much better for me, I have pfsense in VM on Proxmox and I had bandwidth issues with e1000 on pfsense, on VirtIO works perfect. Yeah, on nested enviroment inside VMware its safer to use e1000 (I think VirtIO shouldn't have issues eighter), on bare metal VirtIO is the best choice.

    • @demanuDJ
      @demanuDJ 2 ปีที่แล้ว

      @@VirtualizationHowto oh and if you have faster NICs than 1Gbit/s just also use VirtIO or passthrough NICs to pfsense and for VMs and LXCcontainers inside proxmox use another VirtIO bridge, thats because VirtIO is not limiting your bandwidth to virtualised e1000 hardware

  • @AdrianuX1985
    @AdrianuX1985 2 ปีที่แล้ว +1

    Why not OPNsense?

    • @VirtualizationHowto
      @VirtualizationHowto  2 ปีที่แล้ว +3

      AdrianuX I have this on my list of things to try :)

    • @abb0tt
      @abb0tt 2 ปีที่แล้ว

      the approach is very similar

  • @XtianApi
    @XtianApi 2 หลายเดือนก่อน

    Okay now add a second host to this and show us how everything stays up when you migrate

  • @Redicat
    @Redicat ปีที่แล้ว

    bruh you could of explained to just use WAN interface as lan you do not need to have a seperate lan interface

  • @DennisWard-p2n
    @DennisWard-p2n 2 หลายเดือนก่อน

    Merlin Coves

    • @user-du6vx7ir7m
      @user-du6vx7ir7m 2 หลายเดือนก่อน

      his name was robert thompson

  • @mathewcampisi7594
    @mathewcampisi7594 ปีที่แล้ว

    Seriously Dork, your not going to explain how you got around the dot GZ compression?????

    • @crystalclearsolutions374
      @crystalclearsolutions374 ปีที่แล้ว +1

      No need to be disrespectful, these videos as well as the community are here to help. Just unzip the gz file and the iso should be inside.

    • @grocerylist
      @grocerylist ปีที่แล้ว +6

      If you don't know how to unzip a file, you're probably not going to be virtualizing pfSense in Proxmox.

    • @martynwarry6800
      @martynwarry6800 ปีที่แล้ว +2

      With respect, if you don't understand how to deal with compressed archives then setting up PFSense in a Proxmox VM is too much for you. Slow down and learn the basics before you attempt to tackle stuff like this. Oh and calling the guy a dork when he's obviously way more knowledgable than you is a dick move and one that will discourage people from helping you, and clearly you really need that help.

  • @Nul1Secur1ty
    @Nul1Secur1ty 2 ปีที่แล้ว

    ;)

  • @jeffharwood624
    @jeffharwood624 2 ปีที่แล้ว

    Proxmox is crap. You cannot access it on first run. I've worked with a lot of QEMU and KVM over the years, I've dealt with those problems, now I am unwilling to deal with more of those problems. Been all over the forums found little to no answers. I am unwilling to pay for support. Been down that road too many times. I'm so done with this.

    • @martynwarry6800
      @martynwarry6800 ปีที่แล้ว

      Ok everyone it's time to abandon Proxmox because Jeff here thinks it's crap lol. Hmm but what Jeff is really telling us is that getting a Proxmox server up and running is beyond his skillset and/or patience and he doesn't want to pay for help. Poor Jeff, let's all send him some hugs.. lol

    • @jeffharwood624
      @jeffharwood624 ปีที่แล้ว

      @@martynwarry6800 That's OK for you to think that. The website speaks for itself. I work cyber. We found four bugs in 7.4.0. and 8.0 six. So before you start hating and mocking, understand this...My clients are attorney's. I work for attorney's. They started questioning their legitimacy when they didn't respond. I responded in kind.BTW, these are the same bugs we found in all variants of Ubuntu. Proxmox has a major problem that's brewing as does Ubuntu. One is memory leaks due to the use of inefficient Kernel. In Ubuntu this shows as a root file space error. Why? Generic kernel's are used on Intel Devices, the more optimized kernel's go to AMD. I was asked to investigate this. And finally, we hit Proxmox with AI....We achieved all the goals we had hoped. We placed objects in Proxmox then the AI test with LUX. We extracted not only the key's to the city LUX key's, we extracted the text files AND remove the Kernel too. AND I got me a Goonie as a grand prize. Woo-hoo.

    • @jeffharwood624
      @jeffharwood624 ปีที่แล้ว

      @@martynwarry6800 So were you duped into buying Chinese e waste or or once overpriced AMD products? Just curious. At 75, I have three degrees, Chemistry, Electronics and Computer Science, plus All Cyber Certificates. CCNA on. These are my skill sets. What are yours?