Outcome
You will know which physical port carries management traffic, which bridge guests use, and how to change the configuration with a recovery path. This guide covers an existing supported x86-64 lab host, not an untested PebbleRack device.
Before you start
Draw the path from host port to switch port to router. Record the host IP, prefix, gateway, DNS server, and exact physical interface name shown under Node → System → Network. Have a local keyboard and display or verified out-of-band access before changing the management network. A wrong bridge or gateway can disconnect the web interface. Save the current configuration and schedule changes when guests can tolerate interruption.
Steps
- Read the current layout. A typical fresh installation puts the physical Ethernet interface into a Linux bridge named vmbr0 and assigns the host management address to that bridge. The physical port normally has no separate IP. Proxmox describes a bridge as a software switch: guests attached to it can appear as separate devices on the physical LAN.
- Verify addressing without editing. Compare GUI values with the router LAN subnet and your inventory. Check that no other device holds the proposed static IP. Verify the host is reachable from another LAN device, and that its gateway and DNS are correct. Do not solve reachability by forwarding port 8006 from the internet.
- Plan guest connectivity. For a basic home lab, keep vmbr0 attached to the trusted LAN and give test guests addresses via router DHCP or a documented static range. Record which switch port and VLAN carry that LAN. Do not add a VLAN tag or second bridge unless the switch and router configuration is already known.
- Stage one change. Proxmox stages GUI network edits before applying them. If you must change an IP, bridge port, or gateway, confirm every field and keep the local console available. Select Apply Configuration only after recording old settings. Proxmox may apply changes live with ifupdown2; live does not guarantee uninterrupted access.
- Test from two places. Test the UI from another device, then verify host gateway and DNS resolution. Start a disposable guest and check its network assignment. If the host works but the guest does not, inspect the guest NIC and router lease before changing the host again.
- Document the new state. Update interface, bridge, management IP, switch port, VLAN if used, gateway, and DNS in private inventory.
Check it worked
The UI remains reachable at the documented trusted-LAN address after a fresh session. A test guest attached to vmbr0 reaches the intended network. The host resolves names and reaches its update repository.
If it fails or rollback
Use the local console to compare the current network configuration with the saved one. Fix the specific wrong address, port, or gateway according to Proxmox network instructions. If an edit was only staged, discard it in the UI. Blind reboots do not repair a wrong persistent configuration. Shut down affected guests before another disruptive edit.
Safety and data notes
Keep management on a trusted network and use strong authentication. Treat private IPs, hostnames, and switch maps as sensitive. A bridge alone is not a guest security boundary.
Sources
Official Proxmox documentation checked 2026-09-29: network configuration, default bridge, staged changes, guest network devices.
Next guide
Continue with guide 12 to choose storage before filling the host with guests.