Overview
Virtualizing network firewalls with OPNsense on Proxmox VE allows rapid snapshot backups, resource scalability, and integrated multi-WAN failover.
Proxmox Network Bridge Setup
In /etc/network/interfaces on the Proxmox host, configure linux bridges:
# Physical WAN Bridge
auto vmbr0
iface vmbr0 inet manual
bridge-ports enp3s0
bridge-stp off
bridge-fd 0
# Physical LAN / VLAN Trunk Bridge
auto vmbr1
iface vmbr1 inet manual
bridge-ports enp4s0
bridge-stp off
bridge-fd 0
bridge-vlan-aware yes
OPNsense VM Parameters
| Setting | Value | Description |
|---|---|---|
| OS Type | FreeBSD / Other | OPNsense base OS architecture |
| Cores | 4 Cores | Dedicated CPU sockets/cores |
| RAM | 4096 MB | ECC RAM recommendation |
| Network NIC | VirtIO (paravirtualized) | High throughput 10GbE driver |
WireGuard Tunnel Setup
To establish encrypted remote administration access:
- Navigate to VPN → WireGuard → Instances.
- Generate public/private keypair.
- Add Endpoint Peer
10.0.100.2/32. - Create Firewall rule permitting UDP port
51820.
[ Remote Client ] ----(UDP 51820 / WireGuard)----> [ OPNsense Firewall ] ---> [ Private Subnets ]