ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Virtualization & Host Nodes

Create a KVM VM in Proxmox VE and Assign a Dedicated Public IP: Images, Bridging and VPS Setup

5 steps 12 min read 1 views 0
On this page

Once Proxmox VE is running on your dedicated server, the next job is to create KVM virtual machines in PVE and give each one its own public IP. Using a server with a /24 block as the example, this guide covers uploading an ISO or cloud image, creating a VM from the command line, bridging it through vmbr0, configuring a dedicated IP and gateway inside Debian/Ubuntu and CentOS/Rocky/AlmaLinux guests, and practical tips if you plan to resell VPS.

The examples use 203.0.113.0/24 with gateway 203.0.113.1. Always use the IPs, netmask and gateway assigned to you by IMIDC. The network, gateway and broadcast addresses cannot be given to VMs. If your block is routed to the main IP instead of being on-link, open a ticket to confirm the network setup first.

Step 1: Upload an ISO or cloud image to Proxmox VE

For a manual install, use "local storage → ISO Images → Upload / Download from URL" in the web UI, or download straight into the ISO directory with wget. For fast provisioning, a cloud image plus cloud-init delivers a new VM in under a minute.

cd /var/lib/vz/template/iso
# replace the file name with the current release
wget https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/debian-12.7.0-amd64-netinst.iso
# cloud image for template-based deployment
mkdir -p /var/lib/vz/images/cloud && cd /var/lib/vz/images/cloud
wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2

Step 2: Create a KVM virtual machine in PVE

The qm commands below create VM 101 with 2 vCPUs and 2 GB RAM, a virtio NIC bridged to vmbr0 with the firewall flag enabled, then import the cloud image as the boot disk, add a cloud-init drive and a serial console, and grow the disk by 18 GB. For an ISO install skip the import and attach the ISO with --ide2 local:iso/FILE,media=cdrom.

qm create 101 --name vm101 --memory 2048 --cores 2 --cpu host \
  --net0 virtio,bridge=vmbr0,firewall=1 --scsihw virtio-scsi-pci --ostype l26
qm disk import 101 /var/lib/vz/images/cloud/debian-12-genericcloud-amd64.qcow2 local-lvm
qm set 101 --scsi0 local-lvm:vm-101-disk-0 --boot order=scsi0 \
  --ide2 local-lvm:cloudinit --serial0 socket --vga serial0 --agent enabled=1
qm resize 101 scsi0 +18G

Step 3: Assign a dedicated IP and gateway with cloud-init

With a cloud image, put the IP, gateway, DNS and SSH key into cloud-init; the guest configures itself on first boot. qm terminal attaches to the serial console (Ctrl+O to exit).

qm set 101 --ipconfig0 ip=203.0.113.20/24,gw=203.0.113.1 \
  --nameserver 1.1.1.1 --ciuser root --sshkeys /root/.ssh/authorized_keys
qm start 101
qm terminal 101

Step 4: Configure the public IP inside the VM manually

Guests installed from an ISO need a static IP configured inside the OS. The virtio NIC is usually called ens18; confirm with ip link and pick the method for your distribution.

# Debian / Ubuntu (ifupdown): /etc/network/interfaces
auto ens18
iface ens18 inet static
    address 203.0.113.21/24
    gateway 203.0.113.1
    dns-nameservers 1.1.1.1 8.8.8.8

systemctl restart networking
# Ubuntu (netplan): /etc/netplan/01-static.yaml
network:
  version: 2
  ethernets:
    ens18:
      addresses: [203.0.113.22/24]
      routes:
        - to: default
          via: 203.0.113.1
      nameservers:
        addresses: [1.1.1.1, 8.8.8.8]

netplan apply
# CentOS Stream / Rocky / AlmaLinux (NetworkManager)
nmcli con mod ens18 ipv4.method manual ipv4.addresses 203.0.113.23/24 \
  ipv4.gateway 203.0.113.1 ipv4.dns "1.1.1.1 8.8.8.8"
nmcli con up ens18

Then verify the address and default route, and ping both the gateway and an external host:

ip -br addr
ip route
ping -c 4 203.0.113.1
ping -c 4 1.1.1.1

Step 5: Tips before selling VPS on Proxmox

If you plan to rent VMs to customers, take care of the following:

  • Prevent IP hijacking: enable the PVE firewall ipfilter so each VM can only use its assigned IPs.
  • Oversell carefully: CPU can be overcommitted moderately, but be conservative with RAM and disk and watch NVMe I/O peaks.
  • Back up regularly: use vzdump or Proxmox Backup Server and keep copies on another machine.
  • rDNS and abuse handling: set reverse DNS for every IP and respond to complaints quickly so the block is not blacklisted.
# /etc/pve/firewall/101.fw
[OPTIONS]
enable: 1
ipfilter: 1
policy_in: ACCEPT

[IPSET ipfilter-net0]
203.0.113.20
vzdump 101 --storage local --mode snapshot --compress zstd
Follow IMIDC's terms of service and local law. Do not allow customers to send spam or launch attacks from your VMs; abuse can get the whole IP block blocked.

FAQ

My PVE VM has a public IP but no internet access

Make sure the VM NIC is bridged to vmbr0 and the host itself is online, then check the prefix length and gateway. If the data center binds IPs to MAC addresses, you need a virtual MAC for that IP on the VM NIC; open a ticket to confirm.

The IP set via cloud-init is not applied

After changing cloud-init options run qm cloudinit update 101 or reboot the VM, and make sure the image supports cloud-init.

How many VMs can I run on a /24?

A /24 has 256 addresses; after the network, gateway and broadcast addresses about 253 are usable. Check your allocation notes for the exact number.

Still stuck? Open a ticket and IMIDC 24/7 support will help.

Was this answer helpful?

Related Tutorials