Skip to content

New tutorial - "Building a Virtual Office Network on a Hetzner Dedicated Server with Proxmox, OPNsense and Open vSwitch" - #1525

Open
gushmazuko wants to merge 3 commits into
hetzneronline:masterfrom
gushmazuko:virtual-office-network-proxmox-opnsense-ovs
Open

gushmazuko wants to merge 3 commits into
hetzneronline:masterfrom
gushmazuko:virtual-office-network-proxmox-opnsense-ovs

Conversation

@gushmazuko

@gushmazuko gushmazuko commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Tutorial

Adds a new tutorial: Building a Virtual Office Network on a Hetzner Dedicated Server with Proxmox, OPNsense and Open vSwitch

This is the second part of the Proxmox series and builds directly on "Unattended Proxmox VE Installation on a Hetzner Dedicated Server" — it takes the node that tutorial produces and turns it into a routed virtual office network.

What it covers

  • Hardening the host: rpcbind, SSH drop-ins (custom port, keys only), binding pveproxy away from the public interface, and a default-DROP Proxmox firewall with explicitly verified rules
  • Converting the flat Linux bridge to Open vSwitch (WAN + LAN), including a timed rollback pattern for risky network changes
  • Creating an OPNsense VM entirely from the CLI (qm create), with a serial console as the primary display
  • Installing OPNsense over SSH (no VNC, no GUI) and writing the final config.xml directly into the guest before first boot — including the presence-based schema keys and serial-console generation that cost me the most debugging time
  • Moving Proxmox management to the private LAN, and why the host default route stays on the WAN bridge (asymmetric routing)
  • WireGuard on OPNsense 26.x via the REST API (server, client, firewall rules) and the two host-side details that make "PVE UI over WireGuard" actually work
  • Proving the setup with a disposable DHCP test guest, plus a lockout-recovery ladder

Notes

  • All commands were executed on a real AX41-NVMe server; the article is tested end to end.
  • English only (01.en.md). No images yet — the tutorial is deliberately CLI-first; screenshots can be added later if the review asks for them.
  • Slug/folder: virtual-office-network-proxmox-opnsense-ovs

…cated Server with Proxmox, OPNsense and Open vSwitch"
@svenja11 svenja11 added the review wanted Request a review label Sep 16, 2026
@gushmazuko

Copy link
Copy Markdown
Contributor Author

hello @svenja11, any news?

@svenja11

Copy link
Copy Markdown
Collaborator

Thank you for your contribution @gushmazuko! I started testing your tutorial but ran into an issue in step 4.

root@pve:~# sshpass -p opnsense ssh -o StrictHostKeyChecking=no installer@192.168.1.1
ssh: connect to host 192.168.1.1 port 22: No route to host

Is it possible that there's something missing before running that command?

@gushmazuko

Copy link
Copy Markdown
Contributor Author

Thanks for testing! Step 3 only creates the VM — nothing in step 4 actually started it before the SSH. Fixed in cbf5d66: now it runs qm start 100 first, waits for the live system on the serial console, and pings 192.168.1.1 before connecting.

@svenja11

Copy link
Copy Markdown
Collaborator

Thank you for updating the tutorial @gushmazuko! I tested it again and ran into the following issues:

  • In step 2, I forgot to replace the placeholder IPs in /etc/network/interfaces and was locked out of the system. The safety net didn't do anything, so I had to edit /etc/network/interfaces in rescue mode and reboot.

  • In step 5, I had the following issue:
    • Tutorial
      zpool import -f -R /mnt/opnsense zroot
      ls /mnt/opnsense/conf/config.xml
      
    • My server
      root@pve:/var/lib/vz/template/iso# zpool import -f -R /mnt/opnsense zroot
      
      root@pve:/var/lib/vz/template/iso# ls /mnt/opnsense/conf/config.xml
      ls: cannot access '/mnt/opnsense/conf/config.xml': No such file or directory
      
      root@pve:/var/lib/vz/template/iso# ls -la /mnt/opnsense
      total 12
      drwxr-xr-x 7 root root 7 Sep 28 13:15 .
      drwxr-xr-x 3 root root 3 Sep 28 13:15 ..
      drwxr-xr-x 2 root root 2 Sep 28 13:01 home
      drwxrwxrwt 2 root root 2 Sep 28 13:04 tmp
      drwxr-xr-x 4 root root 4 Sep 28 13:15 usr
      drwxr-xr-x 7 root root 7 Sep 28 13:15 var
      drwxr-xr-x 2 root root 2 Sep 28 13:04 zroot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review wanted Request a review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants