Skip to main content
Infrastructure

Deploying OPNsense Firewall on Proxmox VE with VirtIO Passthrough

A production guide to running virtualized OPNsense firewall on Proxmox VE with High Availability bridges, VLAN sub-interfaces, and WireGuard VPN.

Published ·Updated ·2 min read·Lead Network Engineer
Deploying OPNsense Firewall on Proxmox VE with VirtIO Passthrough

Overview

Virtualizing network firewalls with OPNsense on Proxmox VE allows rapid snapshot backups, resource scalability, and integrated multi-WAN failover.

Proxmox Network Bridge Setup

In /etc/network/interfaces on the Proxmox host, configure linux bridges:

bash
# Physical WAN Bridge
auto vmbr0
iface vmbr0 inet manual
	bridge-ports enp3s0
	bridge-stp off
	bridge-fd 0

# Physical LAN / VLAN Trunk Bridge
auto vmbr1
iface vmbr1 inet manual
	bridge-ports enp4s0
	bridge-stp off
	bridge-fd 0
	bridge-vlan-aware yes

OPNsense VM Parameters

SettingValueDescription
OS TypeFreeBSD / OtherOPNsense base OS architecture
Cores4 CoresDedicated CPU sockets/cores
RAM4096 MBECC RAM recommendation
Network NICVirtIO (paravirtualized)High throughput 10GbE driver

WireGuard Tunnel Setup

To establish encrypted remote administration access:

  1. Navigate to VPN → WireGuard → Instances.
  2. Generate public/private keypair.
  3. Add Endpoint Peer 10.0.100.2/32.
  4. Create Firewall rule permitting UDP port 51820.
text
[ Remote Client ] ----(UDP 51820 / WireGuard)----> [ OPNsense Firewall ] ---> [ Private Subnets ]

Lead Network Engineer

Network Engineer & IT Infrastructure Specialist

Networking • Infrastructure • Monitoring Specialized in high-availability enterprise networks, virtualized infrastructure, and automated Prometheus/Grafana monitoring stacks.

Keep Reading