You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Proxmox环境下单公网IP的虚拟机组网及访问方案咨询

Proxmox环境下单公网IP的虚拟机组网及访问方案咨询

Hi there! This setup is totally achievable—let’s walk through the key steps and considerations based on your needs:

1. 基础内部组网与互联网访问配置

First, you’ll want to build a private internal network for your VMs in Proxmox:

  • Create a new virtual bridge (e.g., vmbr1) in Proxmox’s web UI under Datacenter > Your Node > Network. Don’t bind this bridge to any physical NIC—it’s only for internal VM communication. Assign it a private subnet like 192.168.100.0/24 (pick any RFC1918 range that doesn’t conflict with the datacenter’s 10.8.x.x network).
  • Assign all your VMs an IP address within this private subnet (use static IPs for reliability, or set up a DHCP server if you prefer).
  • Enable IP forwarding on your Proxmox host: edit /etc/sysctl.conf and uncomment or add net.ipv4.ip_forward=1, then run sysctl -p to apply the change immediately.
  • Set up SNAT (Source Network Address Translation) to let VMs access the internet via your public IP. Run these iptables commands (replace enp0s1 with your public-facing NIC name, and 192.168.100.0/24 with your private subnet):
    iptables -t nat -A POSTROUTING -s 192.168.100.0/24 -o enp0s1 -j MASQUERADE
    
    To make this rule persist after reboot, install iptables-persistent and save your rules.

2. Nginx反向代理配置(公网HTTP/HTTPS转发)

For the VM running Nginx:

  • Assign it a static private IP (e.g., 192.168.100.10).
  • On your Proxmox host, set up DNAT (Destination Network Address Translation) to forward public HTTP/HTTPS traffic to this VM. Run these commands:
    # Forward port 80 (HTTP)
    iptables -t nat -A PREROUTING -i enp0s1 -p tcp --dport 80 -j DNAT --to-destination 192.168.100.10:80
    # Forward port 443 (HTTPS)
    iptables -t nat -A PREROUTING -i enp0s1 -p tcp --dport 443 -j DNAT --to-destination 192.168.100.10:443
    
  • Configure your Nginx VM to act as a reverse proxy: set up server blocks for each domain/service, pointing to the private IP of the target VM. For example:
    server {
        listen 80;
        server_name app1.yourdomain.com;
        location / {
            proxy_pass http://192.168.100.11:80; # IP of your app1 VM
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
        }
    }
    
    Don’t forget to point your domain’s DNS records to your public IP 185.18.x.x.

3. SSH访问VM的方案

You have a few secure options here:

  • VPN + Direct SSH: Since you already have a datacenter VPN that lets you access the 10.8.x.x IP, connect to the VPN first, then SSH directly to your Proxmox host’s 10.8.x.x IP. From there, you can SSH to any VM’s private IP (e.g., ssh user@192.168.100.11). This is the most secure method since it’s behind the VPN.
  • Port Forwarding (Public Access, Use Cautiously): If you need SSH access over the public internet, set up DNAT rules on the Proxmox host to forward specific ports to your VMs. For example:
    # Forward public port 2222 to VM 1's SSH port 22
    iptables -t nat -A PREROUTING -i enp0s1 -p tcp --dport 2222 -j DNAT --to-destination 192.168.100.11:22
    
    For security, disable password authentication on all VMs (use SSH keys only) and consider restricting access to specific IP ranges via iptables or your VM’s firewall.
  • Jump Host: Use the Nginx proxy VM as a jump host—SSH to the Nginx VM first (via VPN or port forwarding), then SSH to other VMs from there.

4. Extra Considerations

  • Firewall Rules: Make sure both your Proxmox host’s firewall and each VM’s firewall allow the necessary traffic (e.g., HTTP/HTTPS, SSH, internal network communication).
  • Persistent Rules: As mentioned earlier, use iptables-persistent to save your NAT rules so they survive reboots. Alternatively, you can configure NAT directly in Proxmox’s web UI firewall if you prefer a graphical interface.
  • Monitoring: Keep an eye on your network traffic and set up logging for iptables or Nginx to troubleshoot any issues with forwarding.

备注:内容来源于stack exchange,提问作者ketchupOnWaffles

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 12:24:08