Proxmox Networking Explained: VLANs, Bridges, and vmbr0

Proxmox official documentation screenshot pve-setup-network.png

Proxmox networking is standard Linux networking with a few conventions. Physical NICs plug into Linux bridges (vmbr0, vmbr1 …),
which act as virtual switches; each VM’s virtual NIC plugs into one of those bridges. Add VLAN awareness and bonding and you can model almost any physical network.

This guide explains the default setup, makes a bridge VLAN-aware, tags VMs into VLANs, moves management onto its own VLAN, adds a bond for redundancy, and applies changes
without rebooting. For overlay networks across nodes, see SDN and VXLAN.

Quick answer: tick VLAN aware on vmbr0, set the switch port to trunk, and set a VLAN tag on each VM’s network device.

The Building Blocks

A physical NIC carries traffic to the switch. A Linux bridge connects that NIC to VM virtual NICs. The host’s own IP address lives on the bridge, not on the physical NIC.

architecturepve-network.txt
  switch <--> eno1 (physical) <--> vmbr0 (bridge, host IP) <--> VM101 net0, VM102 net0 ...
Proxmox network building blocks
NIC, bridge, VM NICs

Read the Default Configuration

After installation, /etc/network/interfaces contains one bridge with the host’s IP and the physical NIC as its port.

ini/etc/network/interfaces (default)
auto lo
iface lo inet loopback

iface eno1 inet manual

auto vmbr0
iface vmbr0 inet static
    address 192.168.1.10/24
    gateway 192.168.1.1
    bridge-ports eno1
    bridge-stp off
    bridge-fd 0
Default vmbr0
Host IP on the bridge

Make the Bridge VLAN-Aware

A VLAN-aware bridge carries many VLANs over one uplink. Configure the switch port facing the host as a trunk that carries those VLANs.

iniadditions to vmbr0
    bridge-vlan-aware yes
    bridge-vids 2-4094
NoteIn the web UI this is the VLAN aware checkbox on the bridge under Node → System → Network.
VLAN-aware bridge
One trunk, many VLANs

Tag a VM Into a VLAN

Set the VLAN tag on the VM’s network device. The bridge tags outgoing frames and strips the tag on the way in, so the guest needs no VLAN configuration at all.

bashput VM 101 on VLAN 20
qm set 101 --net0 virtio,bridge=vmbr0,tag=20
VM VLAN tag
The bridge handles tagging

Move Host Management Onto a VLAN

To keep the management interface off the VM networks, move the host IP from vmbr0 to a VLAN sub-interface. Do this from the console, not over SSH on the address you are changing.

ini/etc/network/interfaces (management on VLAN 10)
auto vmbr0
iface vmbr0 inet manual
    bridge-ports eno1
    bridge-stp off
    bridge-fd 0
    bridge-vlan-aware yes
    bridge-vids 2-4094

auto vmbr0.10
iface vmbr0.10 inet static
    address 10.0.10.11/24
    gateway 10.0.10.1
WarningA mistake here cuts off the web UI and SSH. Have IPMI, iLO or a physical console ready.
Management VLAN
Host IP on vmbr0.10

Add a Bond for Redundancy

Bonding two NICs survives a cable, NIC or switch-port failure. active-backup works with any switch; 802.3ad (LACP) adds bandwidth but needs matching switch configuration.

inibond + bridge
auto bond0
iface bond0 inet manual
    bond-slaves eno1 eno2
    bond-mode 802.3ad
    bond-miimon 100
    bond-xmit-hash-policy layer3+4

auto vmbr0
iface vmbr0 inet manual
    bridge-ports bond0
    bridge-stp off
    bridge-fd 0
    bridge-vlan-aware yes
    bridge-vids 2-4094
Bonding
Bridge on top of the bond

Apply Changes Without Rebooting

Proxmox uses ifupdown2, so ifreload -a applies the file in place. The web UI’s Apply Configuration button does the same.

bashapply
cp /etc/network/interfaces /root/interfaces.bak
ifreload -a
Applying network changes
ifreload, keep console access

Verify

Check that VLAN settings are applied to the right ports and that each VLAN reaches its gateway.

bashchecks
bridge vlan show
ip -d link show vmbr0 | grep vlan
cat /proc/net/bonding/bond0 | head -20
ping -c 3 10.0.10.1
Network verification
Per-port VLANs and gateways

What is vmbr0 in Proxmox?

It is the default Linux bridge: a virtual switch connecting the physical NIC to VM network devices. The host’s management IP normally lives on it.

How do I use VLANs in Proxmox?

Make the bridge VLAN-aware, configure the switch port as a trunk, and set a VLAN tag on each VM’s network device.

Do guests need VLAN configuration inside the VM?

No. When the tag is set on the VM’s network device, the bridge handles tagging and the guest sees ordinary untagged traffic.

How do I apply Proxmox network changes without rebooting?

Run ifreload -a or click Apply Configuration in the web UI. Keep console access in case a change cuts off the network.

Which bond mode should I use?

active-backup works with any switch and gives redundancy. 802.3ad (LACP) adds aggregate bandwidth but requires LACP configured on the switch ports.

Cheat Sheet

  • VLAN-aware vmbr0 + trunk port + per-VM tag=
  • Management on vmbr0.X; bond for redundancy; ifreload -a with console ready

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.