Hetzner多公网IP服务器下Proxmox虚拟机指定公网IP上网配置咨询
Hey there, let's work through getting your specific VM online with that dedicated public IP on your Hetzner server. Looking at your current network setup, you're already halfway there—we just need to adjust a few bits to route traffic properly for the VM using your extra public IP range.
Step 1: Confirm Host Bridge & Routing Setup
First, let's double-check your vmbr0 config. You already added the route for your 89.178.66.171/27 range to vmbr0, which is the right direction. Just make sure you're using the correct gateway for that IP segment—Hetzner assigns a unique gateway for each public IP block, which you can find in your Hetzner Robot panel or Cloud Console. For a /27 subnet, it's typically the first IP in the range (e.g., if your range is 89.178.66.161-191, the gateway would be 89.178.66.161).
Your existing vmbr0 config looks solid, but if you want to make the route fully persistent across reboots, you can tweak it like this:
auto vmbr0 iface vmbr0 inet static address 88.188.61.127/27 # Keep your main public IP here, or use one from the 89.178.66.x range bridge-ports none bridge-stp off bridge-fd 0 up ip route add 89.178.66.171/27 dev vmbr0 # Optional: Add gateway for the 89.178.66.x range with a metric to prioritize main gateway # up ip route add default via 89.178.66.161 dev vmbr0 metric 100
(The metric ensures your server's main traffic still uses the enp7s0 gateway unless explicitly routed otherwise.)
Step 2: Configure the VM's Network Interface
Next, hop into your Proxmox GUI for the target VM:
- Go to the VM's Hardware tab, find the network device, and set its Bridge to
vmbr0. - Start the VM, then log into it and configure the static IP in its network config (location varies by OS:
/etc/network/interfacesfor Debian/Ubuntu,/etc/sysconfig/network-scripts/ifcfg-eth0for RHEL/CentOS, etc.).
For a Debian-based VM, the config would look like this:
auto eth0 iface eth0 inet static address 89.178.66.171/27 gateway 89.178.66.161 # Use the Hetzner-provided gateway for this IP range dns-nameservers 185.12.64.1 185.12.64.2 # Hetzner's public DNS, or your preferred ones
Save the config and restart the network service (e.g., systemctl restart networking).
Step 3: Verify Routing & Connectivity
On the host, confirm IP forwarding is enabled (you already have this in your enp7s0 config, but double-check with sysctl net.ipv4.ip_forward—it should return 1).
Then test from the VM:
- Ping the gateway:
ping 89.178.66.161 - Ping an external address:
ping 8.8.8.8 - Check your public IP:
curl ifconfig.me—it should show 89.178.66.171.
Quick Note on Your Existing NAT Rules
Your current iptables rules on enp7s0 route traffic to your 10.10.10.1 VM via NAT. These won't interfere with the vmbr0 traffic since it's a separate bridge with direct public IP routing—so you don't need to modify those unless you want to adjust traffic routing priorities.
If you hit connectivity issues, double-check Hetzner's firewall settings (ensure the 89.178.66.171 IP is allowed) and that no conflicting iptables rules on the host are blocking traffic to vmbr0.
备注:内容来源于stack exchange,提问作者dima1002

