Hetzner Proxmox OPNsense Setup with a Single IP
Hetzner Proxmox OPNsense Setup with a Single IP. Learn Networking, Automation, and Cluster Design with practical Proxmox steps.
The starting point
- The server has a single public IPv4 address
- The Proxmox host is currently reachable on port 8006 and over SSH
- OPNsense runs as a VM that does NAT
- The goal is a smaller attack surface and a hypervisor that is not exposed
The main design question is whether the public IP should stay on Proxmox or go directly to OPNsense.
Recommended architecture for production
- Assign the public IP directly to OPNsense WAN
- Attach the physical NIC (or a bridge) to the OPNsense VM
- Create an internal virtual bridge for the LAN
- Attach Proxmox management to the internal bridge only
- Access everything via VPN
With this layout a firewall sits in front of the hypervisor, and Proxmox is no longer exposed directly.
VPN-only access (best practice)
- Deploy WireGuard on OPNsense
- Block all inbound WAN traffic except the VPN
- Keep every Proxmox port off the public internet
- Manage the host on its private LAN IP over the VPN
The attack surface shrinks a great deal, and you can still manage everything remotely.
Handling the lockout risk
With only one public IP, a mistake in the OPNsense configuration can lock you out.
- Keep the Hetzner Robot or VNC console for emergency access
- Assign a second IP temporarily during setup
- Use the provider firewall to restrict exposure
- Test the VPN before you remove direct access
People often recommend a temporary second IP for the migration.
Alternative approaches
Proxmox handles NAT
- The configuration is simpler
- Use host firewall rules
- Restrict the public IP by source IP
- Run Tailscale or WireGuard on the host
IPv6 deployment
- Hetzner provides a /56 IPv6 range
- Route IPv6 through OPNsense
- Keep IPv4 locked down
- You get more flexibility in the long run
Summary of the security model
- The public IP belongs to the firewall VM
- The hypervisor is internal only
- All administration goes through the VPN
- Port 8006 is not public
- Console access stays available for emergency recovery
Enterprise networks use the same kind of perimeter design.
Frequently asked questions
Should the public IP stay on Proxmox?
Not in the long run. Assign it to OPNsense so the hypervisor is not exposed.
Is VPN-only access realistic?
Yes. It is the most secure approach and the one people recommend most often.
What if OPNsense fails to boot?
Use the Hetzner console tools to get back in, or reassign the networking temporarily.
Is the provider firewall enough?
It adds protection, but a firewall VM in front of the host gives you a cleaner security boundary.
Need help with Proxmox?
Use the form below to get in touch about migrations, troubleshooting, and Proxmox design work.