Getting started

Proxmox VE on a dedicated server: installation and initial setup

Contents

For an administrator who needs several isolated systems on one dedicated server: an accounting system, remote desktops, a website. The result is Proxmox VE 9.2 with an internal network for virtual machines, a closed web interface and scheduled backups.

What you will need#

The current release as of October 2026 is Proxmox VE 9.2, based on Debian 13 “Trixie”.

  • A server with memory to spare: Proxmox VE itself needs at least 2 GB, ZFS about 1 GB more per terabyte of used storage; the rest is for virtual machines (VMs).
  • For path B, a server with Debian 13 (like Proxmox VE 9, we install it before delivery); for path C, a remote console in its Java variant: on request through support; the Lite line may not have one.
  • A fully qualified domain name for the node, for example pve1.example.com: renaming a node later is not easy.

Path A: a server with Proxmox VE 9 preinstalled#

The main and simplest method: the system is already on the server when it is delivered.

  1. In the order comment, specify Proxmox VE 9.
  2. After delivery, the login details are sent to the contacts in the order.
  3. Open https://198.51.100.5:8006 (an example address) and log in with these details.
  4. First close the web interface to the internet (section below), then set up the repositories and update the system.

Path B: on top of Debian 13#

A fallback, for example when the server already runs Debian 13. The commands come from the official Proxmox guide for Debian 13; run them as root. On our servers, log in as the debian user (the password is in the email) and switch to root with sudo -i.

Warning. The installation replaces the kernel and reboots the server. The guide assumes a static address in /etc/network/interfaces, whereas our Linux images are configured through cloud-init, so the server may not come back online after the reboot. Then the remote console or the rescue mode will help — both through support.

  1. The node’s hostname must point to the server’s public address, not to 127.0.1.1. In /etc/hosts replace the 127.0.1.1 line with a line for the server’s address (the address and name are examples; pve1 is what hostname prints):

    127.0.0.1       localhost
    198.51.100.5    pve1.example.com pve1

    Check: hostname --ip-address must print 198.51.100.5.

  2. Add the Proxmox VE No-Subscription repository and the signing key; compare the key’s checksum with the one in the official guide:

    cat > /etc/apt/sources.list.d/pve-install-repo.sources << EOL
    Types: deb
    URIs: http://download.proxmox.com/debian/pve
    Suites: trixie
    Components: pve-no-subscription
    Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg
    EOL
    wget https://enterprise.proxmox.com/debian/proxmox-archive-keyring-trixie.gpg -O /usr/share/keyrings/proxmox-archive-keyring.gpg
    sha256sum /usr/share/keyrings/proxmox-archive-keyring.gpg
  3. Update the system, install the Proxmox kernel and reboot the server:

    apt update && apt full-upgrade
    apt install proxmox-default-kernel
    systemctl reboot
  4. Install Proxmox VE (when postfix asks, choose Local only unless you have a mail server), then remove the Debian kernel and os-prober:

    apt install proxmox-ve postfix open-iscsi chrony
    apt remove linux-image-amd64 'linux-image-6.12*'
    update-grub
    apt remove os-prober
  5. Open https://198.51.100.5:8006 and log in as root. If root has no password, set one with passwd.

Path C: from the ISO through the remote console#

The method Proxmox recommends, for when you need ZFS or your own disk layout: the installer partitions the disks itself. Ask support for the remote console in its Java variant — only that one lets you attach your own ISO image. In the request, give the public IP address you will connect from: the link is valid for a limited time and only from that address.

Warning. The installer erases all data on the selected disks. If the server holds anything you need, make a copy first.

  1. Download the Proxmox VE 9.2 image from proxmox.com and verify its SHA256 checksum.
  2. Attach the image in the console, boot the server from it and choose Install Proxmox VE (Graphical) or, if graphical mode works poorly in the console, Install Proxmox VE (Terminal UI).
  3. At the Target Harddisk step click Options: zfs (RAID1) is a mirror of two disks, ext4 is for a single disk or hardware RAID.
  4. Enter the country, time zone, root password and an email for notifications, and in the network fields Hostname (FQDN), IP Address (CIDR), Gateway and DNS Server the values from support.
  5. After the reboot open https://198.51.100.5:8006 and log in as root.

Repositories and updates#

In the web interface select the node and open Updates → Repositories. After an ISO installation the Enterprise repository is enabled there; it requires a Proxmox subscription, and without one apt update fails with error 401. With a subscription, add the key under Subscription. Without one, disable the Enterprise repositories and use Add to add No-Subscription (after path B it is already there). The Proxmox documentation does not recommend No-Subscription for production servers: its packages get less testing. Update the system with apt full-upgrade, not apt upgrade.

Network: an internal bridge and NAT#

ip route show default shows which interface holds the public address: after an ISO installation it is the vmbr0 bridge, after path B the physical interface. Changes to /etc/network/interfaces are applied with ifreload -a from the ifupdown2 package; if the command is missing, run apt install ifupdown2.

Warning. A mistake in the public interface settings cuts off both SSH and the web interface. Before any change to /etc/network/interfaces, arrange a remote console with support, save a copy of the file and schedule an automatic rollback, as in the steps below.

A simple option that leaves the public interface untouched is an internal bridge with no physical port: VMs get addresses from a private subnet and reach the internet through NAT.

  1. Save a copy of the file: cp /etc/network/interfaces /root/interfaces.bak.
  2. At the end of /etc/network/interfaces add a block modelled on the official Proxmox example. The subnet 10.10.10.0/24 is an example. If ip route show default shows a different outbound interface, put its name in place of vmbr0.

    auto vmbr1
    iface vmbr1 inet static
            address  10.10.10.1/24
            bridge-ports none
            bridge-stp off
            bridge-fd 0
    
            post-up   echo 1 > /proc/sys/net/ipv4/ip_forward
            post-up   iptables -t nat -A POSTROUTING -s '10.10.10.0/24' -o vmbr0 -j MASQUERADE
            post-down iptables -t nat -D POSTROUTING -s '10.10.10.0/24' -o vmbr0 -j MASQUERADE
  3. Check the syntax with ifreload -a -s, schedule an automatic rollback in 5 minutes and apply the changes:

    systemd-run --on-active=300 --unit=net-rollback /bin/sh -c 'cp /root/interfaces.bak /etc/network/interfaces; ifreload -a'
    ifreload -a
  4. Open a new SSH session. If the connection works, cancel the rollback: systemctl stop net-rollback.timer. If it is lost and not back within 5–6 minutes, restore the file from the copy through the remote console.

Attach the VM to vmbr1 and give the guest a static address, for example 10.10.10.2/24, gateway 10.10.10.1 and a public DNS server: there is no DHCP on the bridge.

Public addresses for VMs#

Order additional IPv4 addresses through support: up to 256 per server, up to 128 on Lite. For a VM to use such an address directly, in bridged mode, each address needs a virtual MAC address: support issues it together with the address, netmask and gateway. Do not attach a VM to the bridge with the public address without an issued MAC. The alternative without additional addresses is NAT on the host, as above.

  1. Attach the VM to the bridge with the public address (after an ISO installation, vmbr0) and enter the issued MAC in the MAC address field: Hardware → Network Device → Edit.
  2. In the guest, set the address with a /32 mask and the host’s gateway. An example for Ubuntu 24.04 and 26.04 (a file in /etc/netplan/; the addresses are examples, ip -br link shows the interface name):

    network:
      version: 2
      ethernets:
        ens18:
          addresses: [203.0.113.20/32]
          routes:
            - to: default
              via: 198.51.100.1
              on-link: true
          nameservers:
            addresses: [198.51.100.53]

    Apply the changes with sudo netplan try and confirm with Enter; otherwise they roll back by themselves.

IPv6#

Servers in the main lines get a /64 block (Power and Ultra a /56, Lite a single /128 address); support sends the addresses and the gateway. On the preinstalled system and on our Debian 13 the first IPv6 address is configured during installation. After an ISO installation add an iface vmbr0 inet6 static block with that address and gateway to /etc/network/interfaces, with the same rollback plan.

Close the web interface to the internet#

Port 8006 gives full control over every VM, so, like SSH, it must be reachable only from your own addresses.

Warning. Once enabled at the Datacenter level, the firewall blocks all incoming connections except those explicitly allowed. First open a separate SSH session and keep it open, add your addresses to the management set, and only then enable the firewall. Rollback: in that session or through the remote console run pve-firewall stop, fix the file and run pve-firewall start.

The settings go in /etc/pve/firewall/cluster.fw or in the web interface (Datacenter → Firewall). The addresses are examples:

[OPTIONS]
enable: 1

[ALIASES]
local_network 198.51.100.5

[IPSET management]
203.0.113.10
10.66.0.0/24

[RULES]
IN Ping(ACCEPT)

Addresses in the management set may reach the web interface, SSH and VM consoles; here these are the office address and the VPN subnet. For a single server on a public network the documentation advises setting the local_network alias explicitly, to the server’s own address; otherwise its whole subnet counts as “local”. Keep the Ping(ACCEPT) rule: the data centre checks the server’s availability by pinging it from its own network and without this rule will consider it down.

No static address? Connect through a VPN: WireGuard: a secure channel between the office and the server. If WireGuard runs on the server itself, add the line IN ACCEPT -p udp -dport 51820 to the [RULES] section (an example port).

Two-factor authentication#

Under Datacenter → Permissions → Two Factor add a TOTP second factor for root@pam and generate single-use Recovery Keys — keep them apart from the password. The second factor does not apply to SSH: allow only key-based login there — SSH keys.

Storage: ZFS or LVM#

On a server with two or more disks, the preinstalled Proxmox VE 9 sits by default on all the disks with software RAID 1 (mdadm): each disk has an EFI partition, and these are mirrored too; /boot and the root / are on RAID 1 arrays (usually md2 and md3), and swap is separate on each disk outside the RAID. On models with a hardware RAID controller (the card says “hardware RAID”), the controller’s utility shows the array’s state, for example storcli or MegaCLI.

Proxmox does not officially support mdadm software RAID: the installer does not offer it, and the Proxmox wiki explains that mdraid does not verify data integrity. Proxmox VE does work on it, but the array needs watching: How to check software RAID and disk health. If you need ZFS, install from the ISO (path C); the installer offers these options:

  • ZFS — when the disks are attached directly: mirroring, snapshots, data integrity checks. ZFS is not supported on top of hardware RAID.
  • LVM (the ext4 option in the installer; VM disks go to an LVM-thin pool) — for a single disk or a hardware RAID controller; LVM itself does not protect against a disk failure.

Backing up virtual machines#

The built-in vzdump tool in Snapshot mode backs up a VM without stopping it. A copy on the same server’s disks will not help if that server fails, so attach external storage first.

  1. Datacenter → Storage → Add: add a storage with the Backup content type. On the main lines the server includes backup space on separate storage: attach it as NFS (in the advanced options, NFS Version 3). Support will send the host name and export path and will open access from the server’s address; you set up the copying yourself.
  2. Datacenter → Backup → Add: choose that storage, a schedule (for example 02:30), Snapshot mode, ZSTD compression, and on the Retention tab how many copies to keep.
  3. Run a backup manually and test a restore into a new VM. The VM numbers and the storage name backup are examples; the second command shows the exact archive name.
vzdump 100 --storage backup --mode snapshot --compress zstd
pvesm list backup --content backup
qmrestore backup:backup/vzdump-qemu-100-2026_10_02-02_30_00.vma.zst 900 --unique 1

Keep a second copy somewhere else: The 3-2-1 rule.

How to check the result#

  • pveversion shows pve-manager/9.2, and apt update finishes without errors.
  • After a server reboot ip -br addr show vmbr1 shows the bridge address, and a test VM has internet access.
  • The web interface opens from an allowed address and asks for the second factor, does not open from other addresses, and the server answers ping.
  • The backup job finished with TASK OK, and the restored VM starts.

Common mistakes#

  • The node’s hostname points to 127.0.1.1. Installing proxmox-ve ends with ipcc_send_rec[1] failed: Connection refused errors — fix /etc/hosts.
  • VMs behind NAT lost internet access after the firewall was enabled. For such setups the Proxmox documentation suggests adding conntrack zones to the vmbr1 block (apply them with the same rollback plan):

            post-up   iptables -t raw -I PREROUTING -i fwbr+ -j CT --zone 1
            post-down iptables -t raw -D PREROUTING -i fwbr+ -j CT --zone 1

What next#

In our catalogue the Power, Ultra and Business lines suit virtualization; exact parameters are on the server card in the catalogue. See also the For business page.

Order a remote console, additional addresses and virtual MAC addresses through support: phone +38 044 206 08 08, email info@united.net.ua.