Virtualisierung & Routing 25. Februar 2026 • 8 Min. Lesezeit

Proxmox VE & OPNsense: IPv6 /64 Subnetting (/80 WAN Transit & /96 LAN Segmentierung)

Dedicated Server erhalten von Rechenzentren (wie Hetzner) standardmäßig ein /64 IPv6-Subnetz (z. B. 2a01:4f8:123:4567::/64). Möchte man dieses Präfix nicht per NDP-Proxy verbiegen, sondern echtes, sauberes Routing an eine virtualisierte OPNsense-Firewall durchführen, empfiehlt sich ein präzises Subnetting.

1. Das Subnetz-Konzept (/80 Transit & /96 LAN)

  • Host / WAN-Transit (vmbr0): 2a01:4f8:123:4567:1::/80
    • Proxmox Host Gateway: 2a01:4f8:123:4567:1::1/80
    • OPNsense WAN-Interface: 2a01:4f8:123:4567:1::2/80 (Gateway: ...:1::1)
  • Internes LAN (vmbr1 / VMs & Container): 2a01:4f8:123:4567:2:1::/96
    • OPNsense LAN-Interface: 2a01:4f8:123:4567:2:1::1/96
    • VMs / Container im LAN: 2a01:4f8:123:4567:2:1::10/96 etc.

2. Proxmox Host-Konfiguration (/etc/network/interfaces)

Auf dem Proxmox-Host aktivieren wir das IPv6-Forwarding und routen das nachgelagerte LAN-Subnetz gezielt auf die WAN-IPv6 der OPNsense:

# /etc/sysctl.d/99-ipv6-forwarding.conf
net.ipv6.conf.all.forwarding = 1
net.ipv6.conf.default.forwarding = 1
net.ipv6.conf.all.accept_ra = 2

Die Netzwerkkonfiguration in /etc/network/interfaces:

auto lo
iface lo inet loopback

# Physische Schnittstelle
auto enp7s0
iface enp7s0 inet manual
iface enp7s0 inet6 manual

# Öffentliche Bridge (WAN)
auto vmbr0
iface vmbr0 inet static
    address 195.201.x.y/32
    gateway 195.201.x.1
    bridge-ports enp7s0
    bridge-stp off
    bridge-fd 0

iface vmbr0 inet6 static
    address 2a01:4f8:123:4567:1::1/80
    gateway fe80::1
    # Route für das nachgelagerte LAN-Segment an die OPNsense (WAN-IP: ...:1::2)
    up ip -6 route add 2a01:4f8:123:4567:2:1::/96 via 2a01:4f8:123:4567:1::2

# Interne Bridge (Isoliertes LAN)
auto vmbr1
iface vmbr1 inet manual
    bridge-ports none
    bridge-stp off
    bridge-fd 0

3. Konfiguration in OPNsense

  1. WAN-Schnittstelle (vtnet0 an vmbr0):
    • IPv6 Configuration Type: Static IPv6
    • IPv6 address: 2a01:4f8:123:4567:1::2/80
    • IPv6 Upstream Gateway: 2a01:4f8:123:4567:1::1
  2. LAN-Schnittstelle (vtnet1 an vmbr1):
    • IPv6 Configuration Type: Static IPv6
    • IPv6 address: 2a01:4f8:123:4567:2:1::1/96
  3. Router Advertisements (Services -> Router Advertisements):
    • Modus auf Stateless oder Managed (DHCPv6) setzen, damit VMs im LAN per SLAAC automatisch IPs aus dem /96-Netz erhalten.

Damit ist der gesamte IPv6-Traffic der internen VMs und Container sauber durch die OPNsense gefiltert, ohne dass NAT oder krumme Bridge-Hacks erforderlich sind.

💡 Support & Consulting: Du benötigst Unterstützung bei der Einrichtung deiner Infrastruktur? 👉 tessmann-digital.de